Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 640

Количество 77 640

ubuntu логотип

CVE-2014-6070

почти 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web script or HTML via the hostname in (1) index.php or (2) detail.php.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-6060

около 12 лет назад

The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.

CVSS2: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2014-6055

почти 12 лет назад

Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer message.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2014-6054

почти 12 лет назад

The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) PalmVNCSetScaleFactor or (2) SetScale message.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-6053

больше 11 лет назад

The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a denial of service (memory consumption or daemon crash) via a crafted message that is processed by using a single unchecked malloc.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-6052

больше 11 лет назад

The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitrary code by specifying a large screen size in a (1) FramebufferUpdate, (2) ResizeFrameBuffer, or (3) PalmVNCReSizeFrameBuffer message.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-6051

почти 12 лет назад

Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-6040

почти 12 лет назад

GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte character value of "0xffff" to the iconv function when converting (1) IBM933, (2) IBM935, (3) IBM937, (4) IBM939, or (5) IBM1364 encoded data to UTF-8.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-6029

около 12 лет назад

TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an editCookies action to profile.php.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2014-6028

около 12 лет назад

TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-6027

больше 8 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.4 allow (1) remote attackers to inject arbitrary web script or HTML by leveraging failure to encode file contents when downloading a torrent file or (2) remote authenticated users to inject arbitrary web script or HTML via vectors involving a link to torrent details.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2014-5519

почти 12 лет назад

The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2014-5515

около 12 лет назад

ntopng: Several vulnerabilities fixed upstream in 1.2.1

EPSS: Низкий
ubuntu логотип

CVE-2014-5514

около 12 лет назад

ntopng: Several vulnerabilities fixed upstream in 1.2.1

EPSS: Низкий
ubuntu логотип

CVE-2014-5513

около 12 лет назад

ntopng: Several vulnerabilities fixed upstream in 1.2.1

EPSS: Низкий
ubuntu логотип

CVE-2014-5512

около 12 лет назад

ntopng: Several vulnerabilities fixed upstream in 1.2.1

EPSS: Низкий
ubuntu логотип

CVE-2014-5511

около 12 лет назад

ntopng: Several vulnerabilities fixed upstream in 1.2.1

EPSS: Низкий
ubuntu логотип

CVE-2014-5472

около 12 лет назад

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-5471

около 12 лет назад

Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 image with a CL entry referring to a directory entry that has a CL entry.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-5464

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-6070

Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web script or HTML via the hostname in (1) index.php or (2) detail.php.

CVSS2: 4.3
4%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-6060

The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.

CVSS2: 3.3
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-6055

Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer message.

CVSS2: 6.5
8%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-6054

The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) PalmVNCSetScaleFactor or (2) SetScale message.

CVSS2: 4.3
6%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-6053

The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a denial of service (memory consumption or daemon crash) via a crafted message that is processed by using a single unchecked malloc.

CVSS2: 5
7%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-6052

The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitrary code by specifying a large screen size in a (1) FramebufferUpdate, (2) ResizeFrameBuffer, or (3) PalmVNCReSizeFrameBuffer message.

CVSS2: 7.5
7%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-6051

Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.

CVSS2: 7.5
8%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-6040

GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte character value of "0xffff" to the iconv function when converting (1) IBM933, (2) IBM935, (3) IBM937, (4) IBM939, or (5) IBM1364 encoded data to UTF-8.

CVSS2: 5
7%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-6029

TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an editCookies action to profile.php.

CVSS2: 4.9
2%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-6028

TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.

CVSS2: 4
2%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-6027

Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.4 allow (1) remote attackers to inject arbitrary web script or HTML by leveraging failure to encode file contents when downloading a torrent file or (2) remote authenticated users to inject arbitrary web script or HTML via vectors involving a link to torrent details.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2014-5519

The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp. NOTE: some of these details are obtained from third party information.

CVSS2: 7.5
65%
Средний
почти 12 лет назад
ubuntu логотип
CVE-2014-5515

ntopng: Several vulnerabilities fixed upstream in 1.2.1

около 12 лет назад
ubuntu логотип
CVE-2014-5514

ntopng: Several vulnerabilities fixed upstream in 1.2.1

около 12 лет назад
ubuntu логотип
CVE-2014-5513

ntopng: Several vulnerabilities fixed upstream in 1.2.1

около 12 лет назад
ubuntu логотип
CVE-2014-5512

ntopng: Several vulnerabilities fixed upstream in 1.2.1

около 12 лет назад
ubuntu логотип
CVE-2014-5511

ntopng: Several vulnerabilities fixed upstream in 1.2.1

около 12 лет назад
ubuntu логотип
CVE-2014-5472

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry.

CVSS2: 4
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-5471

Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 image with a CL entry referring to a directory entry that has a CL entry.

CVSS2: 4
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-5464

Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

CVSS2: 4.3
4%
Низкий
около 12 лет назад

Уязвимостей на страницу