Show filters
228 Total Results
Displaying 191-200 of 228
Sort by:
Attacker Value
Unknown

CVE-2014-9660

Disclosure Date: February 08, 2015 (last updated October 05, 2023)
The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted BDF font.
0
Attacker Value
Unknown

CVE-2014-9661

Disclosure Date: February 08, 2015 (last updated October 05, 2023)
type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted Type42 font.
0
Attacker Value
Unknown

CVE-2014-9670

Disclosure Date: February 08, 2015 (last updated October 05, 2023)
Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.
0
Attacker Value
Unknown

CVE-2015-0236

Disclosure Date: January 29, 2015 (last updated October 05, 2023)
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.
0
Attacker Value
Unknown

CVE-2015-0432

Disclosure Date: January 21, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.
0
Attacker Value
Unknown

CVE-2014-7300

Disclosure Date: December 25, 2014 (last updated October 05, 2023)
GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption of all active PrtSc requests, which allows physically proximate attackers to execute arbitrary commands on an unattended workstation by making many PrtSc requests and leveraging a temporary lock outage, and the resulting temporary shell availability, caused by the Linux kernel OOM killer.
0
Attacker Value
Unknown

CVE-2014-8136

Disclosure Date: December 19, 2014 (last updated October 05, 2023)
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-3580

Disclosure Date: December 18, 2014 (last updated October 05, 2023)
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.
0
Attacker Value
Unknown

CVE-2014-8108

Disclosure Date: December 18, 2014 (last updated October 05, 2023)
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that triggers a lookup for a virtual transaction name that does not exist.
0
Attacker Value
Unknown

CVE-2014-9273

Disclosure Date: December 08, 2014 (last updated October 05, 2023)
lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive files, which triggers an out-of-bounds read or write.
0