Show filters
135 Total Results
Displaying 131-135 of 135
Sort by:
Attacker Value
Unknown
CVE-2014-7145
Disclosure Date: September 28, 2014 (last updated October 05, 2023)
The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other impact by deleting the IPC$ share during resolution of DFS referrals.
0
Attacker Value
Unknown
CVE-2014-3528
Disclosure Date: August 19, 2014 (last updated October 05, 2023)
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
0
Attacker Value
Unknown
CVE-2014-4343
Disclosure Date: August 14, 2014 (last updated October 05, 2023)
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via network traffic that appears to come from an intended acceptor, but specifies a security mechanism different from the one proposed by the initiator.
0
Attacker Value
Unknown
CVE-2014-4344
Disclosure Date: August 14, 2014 (last updated October 05, 2023)
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty continuation token at a certain point during a SPNEGO negotiation.
0
Attacker Value
Unknown
CVE-2014-4342
Disclosure Date: July 20, 2014 (last updated October 05, 2023)
MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a GSSAPI application session.
0