Show filters
335 Total Results
Displaying 131-140 of 335
Sort by:
Attacker Value
Unknown
CVE-2014-9585
Disclosure Date: January 09, 2015 (last updated October 05, 2023)
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.
0
Attacker Value
Unknown
CVE-2014-9584
Disclosure Date: January 09, 2015 (last updated October 05, 2023)
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.
0
Attacker Value
Unknown
CVE-2014-3690
Disclosure Date: November 10, 2014 (last updated October 05, 2023)
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm access, as demonstrated by PR_SET_TSC prctl calls within a modified copy of QEMU.
0
Attacker Value
Unknown
CVE-2014-8559
Disclosure Date: November 10, 2014 (last updated October 05, 2023)
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.
0
Attacker Value
Unknown
CVE-2014-3687
Disclosure Date: November 10, 2014 (last updated November 25, 2024)
The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.
0
Attacker Value
Unknown
CVE-2014-3673
Disclosure Date: November 10, 2014 (last updated November 25, 2024)
The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.
0
Attacker Value
Unknown
CVE-2014-6551
Disclosure Date: October 15, 2014 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows local users to affect confidentiality via vectors related to CLIENT:MYSQLADMIN.
0
Attacker Value
Unknown
CVE-2014-6559
Disclosure Date: October 15, 2014 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING.
0
Attacker Value
Unknown
CVE-2014-6496
Disclosure Date: October 15, 2014 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6494.
0
Attacker Value
Unknown
CVE-2014-6494
Disclosure Date: October 15, 2014 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6496.
0