Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 836

Количество 53 836

redhat логотип

CVE-2014-9644

больше 13 лет назад

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2014-9640

около 12 лет назад

oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2014-9639

больше 11 лет назад

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2014-9638

больше 11 лет назад

oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2014-9637

больше 11 лет назад

GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2014-9636

почти 12 лет назад

unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.

CVSS2: 6.8
EPSS: Средний
redhat логотип

CVE-2014-9635

почти 12 лет назад

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-9634

почти 12 лет назад

Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-9623

больше 11 лет назад

OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2014-9622

около 13 лет назад

Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2014-9621

больше 11 лет назад

The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.

CVSS2: 1.9
EPSS: Низкий
redhat логотип

CVE-2014-9620

больше 11 лет назад

The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.

CVSS2: 1.9
EPSS: Низкий
redhat логотип

CVE-2014-9601

больше 11 лет назад

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2014-9585

больше 11 лет назад

The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.

CVSS2: 1.9
EPSS: Низкий
redhat логотип

CVE-2014-9584

больше 11 лет назад

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.

CVSS2: 1.9
EPSS: Низкий
redhat логотип

CVE-2014-9529

больше 11 лет назад

Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that trigger access to a key structure member during garbage collection of a key.

CVSS2: 4.9
EPSS: Низкий
redhat логотип

CVE-2014-9527

больше 11 лет назад

HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-9515

больше 11 лет назад

Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.

CVSS3: 9
EPSS: Низкий
redhat логотип

CVE-2014-9512

больше 10 лет назад

rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-9496

больше 11 лет назад

The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.

CVSS2: 1.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-9644

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.

CVSS2: 2.1
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2014-9640

oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

CVSS2: 2.1
3%
Низкий
около 12 лет назад
redhat логотип
CVE-2014-9639

Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

CVSS2: 2.1
4%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-9638

oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.

CVSS2: 2.1
4%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-9637

GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.

CVSS2: 2.1
2%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-9636

unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.

CVSS2: 6.8
12%
Средний
почти 12 лет назад
redhat логотип
CVE-2014-9635

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

CVSS2: 4.3
3%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-9634

Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.

CVSS2: 4.3
3%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-9623

OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.

CVSS2: 2.1
3%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-9622

Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open.

CVSS3: 7.8
3%
Низкий
около 13 лет назад
redhat логотип
CVE-2014-9621

The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.

CVSS2: 1.9
3%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-9620

The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.

CVSS2: 1.9
5%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-9601

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.

CVSS2: 2.6
5%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-9585

The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.

CVSS2: 1.9
1%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-9584

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.

CVSS2: 1.9
0%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-9529

Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that trigger access to a key structure member during garbage collection of a key.

CVSS2: 4.9
0%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-9527

HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.

CVSS2: 4.3
8%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-9515

Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.

CVSS3: 9
6%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-9512

rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.

CVSS2: 4.3
6%
Низкий
больше 10 лет назад
redhat логотип
CVE-2014-9496

The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.

CVSS2: 1.2
1%
Низкий
больше 11 лет назад

Уязвимостей на страницу