Show filters
69 Total Results
Displaying 1-10 of 69
Sort by:
Attacker Value
Unknown

CVE-2014-8129

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.
0
Attacker Value
Unknown

CVE-2014-8130

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.
0
Attacker Value
Unknown

CVE-2015-3329

Disclosure Date: June 09, 2015 (last updated October 05, 2023)
Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) phar, or (3) ZIP archive.
0
Attacker Value
Unknown

CVE-2015-2787

Disclosure Date: March 30, 2015 (last updated October 05, 2023)
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages use of the unset function within an __wakeup function, a related issue to CVE-2015-0231.
0
Attacker Value
Unknown

CVE-2014-3583

Disclosure Date: December 15, 2014 (last updated October 05, 2023)
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
0
Attacker Value
Unknown

CVE-2014-4453

Disclosure Date: November 18, 2014 (last updated October 05, 2023)
Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight or Safari, which might allow remote attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-4460

Disclosure Date: November 18, 2014 (last updated October 05, 2023)
CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading cache files.
0
Attacker Value
Unknown

CVE-2014-4458

Disclosure Date: November 18, 2014 (last updated October 05, 2023)
The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might allow remote attackers to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-4461

Disclosure Date: November 18, 2014 (last updated October 05, 2023)
The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted application.
0
Attacker Value
Unknown

CVE-2014-8517

Disclosure Date: November 17, 2014 (last updated October 05, 2023)
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.
0