Show filters
490 Total Results
Displaying 411-420 of 490
Sort by:
Attacker Value
Unknown

CVE-2014-7154

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-7155

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges via vectors involving an (1) HLT, (2) LGDT, (3) LIDT, or (4) LMSW instruction.
0
Attacker Value
Unknown

CVE-2014-6051

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2014-6055

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer message.
0
Attacker Value
Unknown

CVE-2014-2524

Disclosure Date: August 20, 2014 (last updated October 05, 2023)
The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.
0
Attacker Value
Unknown

CVE-2014-0103

Disclosure Date: July 29, 2014 (last updated October 05, 2023)
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
0
Attacker Value
Unknown

CVE-2014-4909

Disclosure Date: July 29, 2014 (last updated October 05, 2023)
Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.
0
Attacker Value
Unknown

CVE-2014-3537

Disclosure Date: July 23, 2014 (last updated October 05, 2023)
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.
0
Attacker Value
Unknown

CVE-2014-4341

Disclosure Date: July 20, 2014 (last updated October 05, 2023)
MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.
0
Attacker Value
Unknown

CVE-2014-3499

Disclosure Date: July 11, 2014 (last updated October 05, 2023)
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.
0