Show filters
490 Total Results
Displaying 401-410 of 490
Sort by:
Attacker Value
Unknown

CVE-2014-8503

Disclosure Date: December 09, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.
0
Attacker Value
Unknown

CVE-2014-8737

Disclosure Date: December 09, 2014 (last updated October 05, 2023)
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
0
Attacker Value
Unknown

CVE-2014-8990

Disclosure Date: December 05, 2014 (last updated October 05, 2023)
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
0
Attacker Value
Unknown

CVE-2014-9093

Disclosure Date: November 26, 2014 (last updated October 05, 2023)
LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.
0
Attacker Value
Unknown

CVE-2014-7821

Disclosure Date: November 24, 2014 (last updated October 05, 2023)
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
0
Attacker Value
Unknown

CVE-2013-0334

Disclosure Date: October 31, 2014 (last updated October 05, 2023)
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
0
Attacker Value
Unknown

CVE-2014-1573

Disclosure Date: October 13, 2014 (last updated October 05, 2023)
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote attackers to conduct cross-site scripting (XSS) attacks by sending three values for a single parameter name.
0
Attacker Value
Unknown

CVE-2014-1572

Disclosure Date: October 13, 2014 (last updated October 05, 2023)
The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.
0
Attacker Value
Unknown

CVE-2014-1571

Disclosure Date: October 13, 2014 (last updated October 05, 2023)
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveraging a role as a flag recipient, related to Bug.pm, Flag.pm, and a mail template.
0
Attacker Value
Unknown

CVE-2014-6394

Disclosure Date: October 08, 2014 (last updated October 05, 2023)
visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.
0