Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 640

Количество 77 640

ubuntu логотип

CVE-2014-9634

почти 9 лет назад

Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9630

больше 6 лет назад

The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted length value.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9629

больше 6 лет назад

Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9628

больше 6 лет назад

The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9627

больше 6 лет назад

The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large box size.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9626

больше 6 лет назад

Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a box size less than 7.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9625

больше 6 лет назад

The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted update status file, aka an "integer truncation" vulnerability.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9624

почти 9 лет назад

CAPTCHA bypass vulnerability in MantisBT before 1.2.19.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-9623

больше 11 лет назад

OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-9622

больше 11 лет назад

Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9621

больше 11 лет назад

The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-9620

больше 11 лет назад

The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-9604

больше 11 лет назад

libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Ut Video data, related to the (1) restore_median and (2) restore_median_il functions.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-9603

больше 11 лет назад

The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the frame width, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Sierra VMD video data.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-9602

больше 11 лет назад

libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words array dimensions that do not satisfy a required mathematical relationship, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted X-Face image data.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-9601

больше 11 лет назад

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-9598

больше 11 лет назад

The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9597

больше 11 лет назад

The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9587

больше 11 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-9586

больше 11 лет назад

The root cause of these vulnerabilities is a lack of bounds checking in protocol parsing C++ code emitted by the binpac utility.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-9634

Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.

CVSS3: 5.3
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2014-9630

The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted length value.

CVSS3: 7.8
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-9629

Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.

CVSS3: 7.8
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-9628

The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7.

CVSS3: 7.8
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-9627

The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large box size.

CVSS3: 7.8
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-9626

Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a box size less than 7.

CVSS3: 7.8
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-9625

The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted update status file, aka an "integer truncation" vulnerability.

CVSS3: 7.8
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-9624

CAPTCHA bypass vulnerability in MantisBT before 1.2.19.

CVSS3: 7.5
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2014-9623

OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.

CVSS2: 4
3%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9622

Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open.

CVSS2: 6.8
3%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9621

The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string.

CVSS2: 5
3%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9620

The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes.

CVSS2: 5
5%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9604

libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Ut Video data, related to the (1) restore_median and (2) restore_median_il functions.

CVSS2: 7.5
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9603

The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the frame width, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Sierra VMD video data.

CVSS2: 7.5
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9602

libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words array dimensions that do not satisfy a required mathematical relationship, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted X-Face image data.

CVSS2: 7.5
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9601

Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.

CVSS2: 5
5%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9598

The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file.

CVSS2: 6.8
6%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9597

The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.

CVSS2: 6.8
7%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9587

Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.

CVSS2: 6.8
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9586

The root cause of these vulnerabilities is a lack of bounds checking in protocol parsing C++ code emitted by the binpac utility.

больше 11 лет назад

Уязвимостей на страницу