Show filters
511 Total Results
Displaying 61-70 of 511
Sort by:
Attacker Value
Unknown

CVE-2014-9529

Disclosure Date: January 09, 2015 (last updated March 15, 2024)
Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that trigger access to a key structure member during garbage collection of a key.
0
Attacker Value
Unknown

CVE-2014-9584

Disclosure Date: January 09, 2015 (last updated October 05, 2023)
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.
0
Attacker Value
Unknown

CVE-2014-8109

Disclosure Date: December 29, 2014 (last updated October 05, 2023)
mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.
0
Attacker Value
Unknown

CVE-2014-8116

Disclosure Date: December 17, 2014 (last updated October 05, 2023)
The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.
0
Attacker Value
Unknown

CVE-2014-8117

Disclosure Date: December 17, 2014 (last updated October 05, 2023)
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-9322

Disclosure Date: December 17, 2014 (last updated October 05, 2023)
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.
Attacker Value
Unknown

CVE-2014-5353

Disclosure Date: December 16, 2014 (last updated October 05, 2023)
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via a successful LDAP query with no results, as demonstrated by using an incorrect object type for a password policy.
0
Attacker Value
Unknown

CVE-2014-3583

Disclosure Date: December 15, 2014 (last updated October 05, 2023)
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
0
Attacker Value
Unknown

CVE-2014-8501

Disclosure Date: December 09, 2014 (last updated October 05, 2023)
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
0
Attacker Value
Unknown

CVE-2014-8485

Disclosure Date: December 09, 2014 (last updated October 05, 2023)
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
0