Show filters
433 Total Results
Displaying 211-220 of 433
Sort by:
Attacker Value
Unknown

CVE-2014-3687

Disclosure Date: November 10, 2014 (last updated November 25, 2024)
The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.
Attacker Value
Unknown

CVE-2014-3610

Disclosure Date: November 10, 2014 (last updated October 05, 2023)
The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the wrmsr_interception function in arch/x86/kvm/svm.c and the handle_wrmsr function in arch/x86/kvm/vmx.c.
Attacker Value
Unknown

CVE-2014-3673

Disclosure Date: November 10, 2014 (last updated November 25, 2024)
The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.
Attacker Value
Unknown

CVE-2014-3693

Disclosure Date: November 07, 2014 (last updated October 05, 2023)
Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.
0
Attacker Value
Unknown

CVE-2014-8483

Disclosure Date: November 06, 2014 (last updated October 05, 2023)
The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.
0
Attacker Value
Unknown

CVE-2014-8080

Disclosure Date: November 03, 2014 (last updated October 05, 2023)
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.
0
Attacker Value
Unknown

CVE-2014-3615

Disclosure Date: November 01, 2014 (last updated October 05, 2023)
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
0
Attacker Value
Unknown

CVE-2014-3694

Disclosure Date: October 29, 2014 (last updated October 05, 2023)
The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5025

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.
0
Attacker Value
Unknown

CVE-2014-5026

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input Method Name, or (5) Host Templates Name in a delete action; (6) Data Source Title; (7) Graph Title; or (8) Graph Template Name in a delete or (9) duplicate action.
0