Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 640

Количество 77 640

ubuntu логотип

CVE-2014-4233

около 12 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRREP.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-4228

около 12 лет назад

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.34, 4.2.26, and 4.3.12 allows local users to affect confidentiality, integrity, and availability via vectors related to Graphics driver (WDDM) for Windows guests.

CVSS2: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2014-4227

около 12 лет назад

Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2014-4223

около 12 лет назад

Unspecified vulnerability in Oracle Java SE 7u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-2483.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2014-4221

около 12 лет назад

Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect confidentiality via unknown vectors related to Libraries.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-4220

около 12 лет назад

Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-4208.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-4219

около 12 лет назад

Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2014-4218

около 12 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect integrity via unknown vectors related to Libraries.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-4216

около 12 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2014-4214

около 12 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRSP.

CVSS2: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2014-4209

около 12 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality and integrity via vectors related to JMX.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2014-4208

около 12 лет назад

Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-4220.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2014-4207

около 12 лет назад

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2014-4199

около 12 лет назад

vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.

CVSS2: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2014-4174

около 12 лет назад

wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a large packet.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2014-4172

больше 6 лет назад

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2014-4171

около 12 лет назад

mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE madvise call or (2) an FALLOC_FL_PUNCH_HOLE fallocate call.

CVSS2: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2014-4168

около 12 лет назад

(1) iodined.c and (2) user.c in iodine before 0.7.0 allows remote attackers to bypass authentication by continuing execution after an error has been triggering.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-4167

около 12 лет назад

The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 private subnet to a L3 router.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2014-4165

около 12 лет назад

Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in a list action to plugins/rrdPlugin.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-4233

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRREP.

CVSS2: 4
3%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4228

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.34, 4.2.26, and 4.3.12 allows local users to affect confidentiality, integrity, and availability via vectors related to Graphics driver (WDDM) for Windows guests.

CVSS2: 4.4
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4227

Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

CVSS2: 10
5%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4223

Unspecified vulnerability in Oracle Java SE 7u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-2483.

CVSS2: 9.3
5%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4221

Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect confidentiality via unknown vectors related to Libraries.

CVSS2: 4.3
3%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4220

Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-4208.

CVSS2: 5
3%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4219

Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

CVSS2: 9.3
6%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4218

Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect integrity via unknown vectors related to Libraries.

CVSS2: 5
4%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4216

Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

CVSS2: 9.3
5%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4214

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRSP.

CVSS2: 3.3
3%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4209

Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality and integrity via vectors related to JMX.

CVSS2: 6.4
4%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4208

Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-4220.

CVSS2: 2.6
3%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4207

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR.

CVSS2: 4
4%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4199

vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.

CVSS2: 6.3
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4174

wiretap/libpcap.c in the libpcap file parser in Wireshark 1.10.x before 1.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted packet-trace file that includes a large packet.

CVSS2: 9.3
6%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4172

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.

CVSS3: 9.8
6%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-4171

mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE madvise call or (2) an FALLOC_FL_PUNCH_HOLE fallocate call.

CVSS2: 4.7
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4168

(1) iodined.c and (2) user.c in iodine before 0.7.0 allows remote attackers to bypass authentication by continuing execution after an error has been triggering.

CVSS2: 5
4%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4167

The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 private subnet to a L3 router.

CVSS2: 3.5
2%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-4165

Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in a list action to plugins/rrdPlugin.

CVSS2: 4.3
2%
Низкий
около 12 лет назад

Уязвимостей на страницу