Show filters
252 Total Results
Displaying 211-220 of 252
Sort by:
Attacker Value
Unknown
CVE-2014-3639
Disclosure Date: September 22, 2014 (last updated December 28, 2023)
The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection consumption and prevention of new connections) via a large number of incomplete connections.
0
Attacker Value
Unknown
CVE-2014-3635
Disclosure Date: September 22, 2014 (last updated December 28, 2023)
Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one more file descriptor than the limit, which triggers a heap-based buffer overflow or an assertion failure.
0
Attacker Value
Unknown
CVE-2014-3985
Disclosure Date: September 11, 2014 (last updated October 05, 2023)
The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remote attackers to cause a denial of service (crash) via crafted headers that trigger an out-of-bounds read.
0
Attacker Value
Unknown
CVE-2014-2527
Disclosure Date: August 26, 2014 (last updated October 05, 2023)
kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a " (double quote) character in the directory name, a different vulnerability than CVE-2014-2528.
0
Attacker Value
Unknown
CVE-2014-0481
Disclosure Date: August 26, 2014 (last updated October 05, 2023)
The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.
0
Attacker Value
Unknown
CVE-2014-2528
Disclosure Date: August 26, 2014 (last updated October 05, 2023)
kcleanup.cpp in KDirStat 2.7.3 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a ' (single quote) character in the directory name, a different vulnerability than CVE-2014-2527.
0
Attacker Value
Unknown
CVE-2013-4159
Disclosure Date: August 06, 2014 (last updated October 05, 2023)
ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp file vulnerabilities" in (1) tcp/tcp_connect.c, (2) server/eventscript.c, (3) tools/ctdb_diagnostics, (4) config/gdb_backtrace, and (5) include/ctdb_private.h.
0
Attacker Value
Unknown
CVE-2014-3533
Disclosure Date: July 19, 2014 (last updated December 28, 2023)
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invalid file descriptor.
0
Attacker Value
Unknown
CVE-2014-4258
Disclosure Date: July 17, 2014 (last updated October 05, 2023)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.
0
Attacker Value
Unknown
CVE-2014-3479
Disclosure Date: July 09, 2014 (last updated October 05, 2023)
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.
0