Show filters
252 Total Results
Displaying 231-240 of 252
Sort by:
Attacker Value
Unknown

CVE-2014-1498

Disclosure Date: March 19, 2014 (last updated October 05, 2023)
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use algorithm.
0
Attacker Value
Unknown

CVE-2014-1499

Disclosure Date: March 19, 2014 (last updated October 05, 2023)
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.
0
Attacker Value
Unknown

CVE-2014-1500

Disclosure Date: March 19, 2014 (last updated October 05, 2023)
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.
0
Attacker Value
Unknown

CVE-2014-1494

Disclosure Date: March 19, 2014 (last updated October 05, 2023)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown

CVE-2014-2270

Disclosure Date: March 14, 2014 (last updated October 05, 2023)
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
0
Attacker Value
Unknown

CVE-2014-0081

Disclosure Date: February 20, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) number_to_percentage, or (c) number_to_human helper.
0
Attacker Value
Unknown

CVE-2011-4093

Disclosure Date: February 10, 2014 (last updated October 05, 2023)
Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user is provided.
0
Attacker Value
Unknown

CVE-2012-2328

Disclosure Date: February 10, 2014 (last updated October 05, 2023)
internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Information Model (CIM) Client (aka sblim-cim-client2) before 2.1.12 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML file.
0
Attacker Value
Unknown

CVE-2013-2191

Disclosure Date: February 08, 2014 (last updated October 05, 2023)
python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-1484

Disclosure Date: February 06, 2014 (last updated October 05, 2023)
Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitive information via a crafted application.
0