Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 640

Количество 77 640

ubuntu логотип

CVE-2014-8399

почти 12 лет назад

The default configuration in systemd-shim 8 enables the Abandon debugging clause, which allows local users to cause a denial of service via unspecified vectors.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2014-8369

почти 12 лет назад

The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS privileges. NOTE: this vulnerability exists because of an incorrect fix for CVE-2014-3601.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2014-8360

больше 11 лет назад

Directory traversal vulnerability in inc/autoload.function.php in GLPI before 0.84.8 allows remote attackers to include and execute arbitrary local files via a .._ (dot dot underscore) in an item type to the getItemForItemtype, as demonstrated by the itemtype parameter in ajax/common.tabs.php.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8355

больше 9 лет назад

PCX parser code in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8354

больше 9 лет назад

The HorizontalFilter function in resize.c in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8350

почти 12 лет назад

Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{literal}<{/literal}script language=php>" in a template.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8333

почти 12 лет назад

The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-8326

почти 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.5, 4.1.x before 4.1.14.6, and 4.2.x before 4.2.10.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name, related to the libraries/DatabaseInterface.class.php code for SQL debug output and the js/server_status_monitor.js code for the server monitor page.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8324

почти 9 лет назад

network.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via a response with a crafted length parameter.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8323

почти 9 лет назад

buddy-ng.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via a response with a crafted length parameter.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8322

больше 6 лет назад

Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2014-8321

больше 6 лет назад

Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local users to execute arbitrary code or gain privileges via unspecified vectors.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2014-8298

почти 12 лет назад

The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8275

больше 11 лет назад

OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2014-8242

почти 11 лет назад

librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birthday attack.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2014-8184

около 7 лет назад

A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2014-8182

больше 6 лет назад

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8181

почти 7 лет назад

The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8179

больше 6 лет назад

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-8178

больше 6 лет назад

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-8399

The default configuration in systemd-shim 8 enables the Abandon debugging clause, which allows local users to cause a denial of service via unspecified vectors.

CVSS2: 2.1
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-8369

The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS privileges. NOTE: this vulnerability exists because of an incorrect fix for CVE-2014-3601.

CVSS3: 7.8
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-8360

Directory traversal vulnerability in inc/autoload.function.php in GLPI before 0.84.8 allows remote attackers to include and execute arbitrary local files via a .._ (dot dot underscore) in an item type to the getItemForItemtype, as demonstrated by the itemtype parameter in ajax/common.tabs.php.

CVSS2: 7.5
3%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-8355

PCX parser code in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).

CVSS3: 5.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2014-8354

The HorizontalFilter function in resize.c in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.

CVSS3: 6.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2014-8350

Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{literal}<{/literal}script language=php>" in a template.

CVSS2: 7.5
3%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-8333

The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.

CVSS2: 4
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-8326

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.5, 4.1.x before 4.1.14.6, and 4.2.x before 4.2.10.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name, related to the libraries/DatabaseInterface.class.php code for SQL debug output and the js/server_status_monitor.js code for the server monitor page.

CVSS2: 3.5
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-8324

network.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via a response with a crafted length parameter.

CVSS3: 7.5
4%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2014-8323

buddy-ng.c in Aircrack-ng before 1.2 Beta 3 allows remote attackers to cause a denial of service (segmentation fault) via a response with a crafted length parameter.

CVSS3: 7.5
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2014-8322

Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.

CVSS3: 9.8
24%
Средний
больше 6 лет назад
ubuntu логотип
CVE-2014-8321

Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local users to execute arbitrary code or gain privileges via unspecified vectors.

CVSS3: 7.8
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-8298

The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.

CVSS2: 7.5
3%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-8275

OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.

CVSS2: 5
16%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-8242

librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birthday attack.

CVSS2: 5.8
3%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2014-8184

A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.

CVSS3: 7.8
2%
Низкий
около 7 лет назад
ubuntu логотип
CVE-2014-8182

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.

CVSS3: 7.5
3%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-8181

The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.

CVSS3: 5.5
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2014-8179

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.

CVSS3: 7.5
3%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-8178

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.

CVSS3: 5.5
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу