Show filters
433 Total Results
Displaying 231-240 of 433
Sort by:
Attacker Value
Unknown

CVE-2014-4943

Disclosure Date: July 19, 2014 (last updated January 20, 2024)
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.
0
Attacker Value
Unknown

CVE-2014-4258

Disclosure Date: July 17, 2014 (last updated October 05, 2023)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.
0
Attacker Value
Unknown

CVE-2014-0207

Disclosure Date: July 09, 2014 (last updated October 05, 2023)
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.
0
Attacker Value
Unknown

CVE-2014-3479

Disclosure Date: July 09, 2014 (last updated October 05, 2023)
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.
0
Attacker Value
Unknown

CVE-2014-3480

Disclosure Date: July 09, 2014 (last updated October 05, 2023)
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.
0
Attacker Value
Unknown

CVE-2014-3487

Disclosure Date: July 09, 2014 (last updated October 05, 2023)
The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.
0
Attacker Value
Unknown

CVE-2014-0247

Disclosure Date: July 03, 2014 (last updated October 05, 2023)
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
0
Attacker Value
Unknown

CVE-2014-4617

Disclosure Date: June 25, 2014 (last updated October 05, 2023)
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.
0
Attacker Value
Unknown

CVE-2014-4049

Disclosure Date: June 18, 2014 (last updated October 05, 2023)
Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns_get_record function.
0
Attacker Value
Unknown

CVE-2014-3730

Disclosure Date: May 16, 2014 (last updated October 05, 2023)
The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as demonstrated by "http:\\\djangoproject.com."
0