Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 558

Количество 77 558

ubuntu логотип

CVE-2014-3005

больше 8 лет назад

XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2014-3004

около 12 лет назад

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-2986

больше 12 лет назад

The vgic_distr_mmio_write function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen 4.4.x, when running on an ARM system, allows local guest users to cause a denial of service (NULL pointer dereference and host crash) via unspecified vectors.

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2014-2983

больше 12 лет назад

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-2980

больше 12 лет назад

Tools/gdomap.c in gdomap in GNUstep Base 1.24.6 and earlier, when run in daemon mode, does not properly handle the file descriptor for the logger, which allows remote attackers to cause a denial of service (abort) via an invalid request.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-2978

около 12 лет назад

The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2014-2977

около 12 лет назад

Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2014-2972

около 12 лет назад

expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2014-2957

около 12 лет назад

The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-2915

больше 12 лет назад

Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of service (host or guest crash) via unspecified vectors, related to (1) cache control, (2) coprocessors, (3) debug registers, and (4) other unspecified registers.

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2014-2914

больше 6 лет назад

fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2014-2913

больше 12 лет назад

Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. NOTE: this issue is disputed by multiple parties. It has been reported that the vendor allows newlines as "expected behavior." Also, this issue can only occur when the administrator enables the "dont_blame_nrpe" option in nrpe.conf despite the "HIGH security risk" warning within the comments

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2014-2907

больше 12 лет назад

The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-2906

больше 6 лет назад

The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name.

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2014-2905

больше 12 лет назад

fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2014-2904

почти 7 лет назад

wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-2902

почти 7 лет назад

wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-2901

почти 7 лет назад

wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-2894

больше 12 лет назад

Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2014-2893

больше 12 лет назад

The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack on temporary directories with predictable names.

CVSS2: 1.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-3005

XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.

CVSS3: 9.8
5%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2014-3004

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

CVSS2: 4.3
8%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-2986

The vgic_distr_mmio_write function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen 4.4.x, when running on an ARM system, allows local guest users to cause a denial of service (NULL pointer dereference and host crash) via unspecified vectors.

CVSS2: 5.5
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2014-2983

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.

CVSS2: 5
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2014-2980

Tools/gdomap.c in gdomap in GNUstep Base 1.24.6 and earlier, when run in daemon mode, does not properly handle the file descriptor for the logger, which allows remote attackers to cause a denial of service (abort) via an invalid request.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2014-2978

The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write.

CVSS2: 10
6%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-2977

Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow.

CVSS2: 10
7%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-2972

expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.

CVSS2: 4.6
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-2957

The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.

CVSS2: 6.8
5%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-2915

Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of service (host or guest crash) via unspecified vectors, related to (1) cache control, (2) coprocessors, (3) debug registers, and (4) other unspecified registers.

CVSS2: 5.5
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2014-2914

fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.

CVSS3: 9.8
3%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-2913

Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. NOTE: this issue is disputed by multiple parties. It has been reported that the vendor allows newlines as "expected behavior." Also, this issue can only occur when the administrator enables the "dont_blame_nrpe" option in nrpe.conf despite the "HIGH security risk" warning within the comments

CVSS2: 7.5
15%
Средний
больше 12 лет назад
ubuntu логотип
CVE-2014-2907

The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2014-2906

The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name.

CVSS3: 7
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-2905

fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.

CVSS2: 6.9
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2014-2904

wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2014-2902

wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2014-2901

wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2014-2894

Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a buffer underflow and memory corruption.

CVSS2: 7.2
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2014-2893

The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack on temporary directories with predictable names.

CVSS2: 1.9
0%
Низкий
больше 12 лет назад

Уязвимостей на страницу