Show filters
511 Total Results
Displaying 81-90 of 511
Sort by:
Attacker Value
Unknown
CVE-2014-3689
Disclosure Date: November 14, 2014 (last updated October 05, 2023)
The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.
0
Attacker Value
Unknown
CVE-2014-7815
Disclosure Date: November 14, 2014 (last updated October 05, 2023)
The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
0
Attacker Value
Unknown
CVE-2014-3611
Disclosure Date: November 10, 2014 (last updated October 05, 2023)
Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS crash) by leveraging incorrect PIT emulation.
0
Attacker Value
Unknown
CVE-2014-3610
Disclosure Date: November 10, 2014 (last updated October 05, 2023)
The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the wrmsr_interception function in arch/x86/kvm/svm.c and the handle_wrmsr function in arch/x86/kvm/vmx.c.
0
Attacker Value
Unknown
CVE-2014-3640
Disclosure Date: November 07, 2014 (last updated October 05, 2023)
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.
0
Attacker Value
Unknown
CVE-2014-3710
Disclosure Date: November 05, 2014 (last updated October 05, 2023)
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
0
Attacker Value
Unknown
CVE-2014-3660
Disclosure Date: November 04, 2014 (last updated October 05, 2023)
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.
0
Attacker Value
Unknown
CVE-2014-3615
Disclosure Date: November 01, 2014 (last updated October 05, 2023)
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
0
Attacker Value
Unknown
CVE-2014-0476
Disclosure Date: October 25, 2014 (last updated October 05, 2023)
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.
0
Attacker Value
Unknown
CVE-2014-3564
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to "different line lengths in a specific order."
0