Show filters
335 Total Results
Displaying 1-10 of 335
Sort by:
Attacker Value
High
CVE-2014-0160 (AKA: Heartbleed)
Disclosure Date: April 07, 2014 (last updated July 03, 2024)
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
0
Attacker Value
Unknown
CVE-2014-3566
Disclosure Date: October 15, 2014 (last updated November 25, 2024)
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
1
Attacker Value
Very High
CVE-2012-1535
Disclosure Date: August 15, 2012 (last updated July 17, 2024)
Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploited in the wild in August 2012 with SWF content in a Word document.
0
Attacker Value
Unknown
CVE-2014-1958
Disclosure Date: February 06, 2020 (last updated November 28, 2024)
Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030.
0
Attacker Value
Unknown
CVE-2014-2030
Disclosure Date: February 06, 2020 (last updated November 28, 2024)
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-1947.
0
Attacker Value
Unknown
CVE-2006-7246
Disclosure Date: January 27, 2020 (last updated November 28, 2024)
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
0
Attacker Value
Unknown
CVE-2012-2736
Disclosure Date: December 26, 2019 (last updated November 27, 2024)
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
0
Attacker Value
Unknown
CVE-2016-9958
Disclosure Date: April 12, 2017 (last updated November 08, 2023)
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
0
Attacker Value
Unknown
CVE-2016-9959
Disclosure Date: April 12, 2017 (last updated November 08, 2023)
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
0
Attacker Value
Unknown
CVE-2016-9957
Disclosure Date: April 12, 2017 (last updated November 08, 2023)
Stack-based buffer overflow in game-music-emu before 0.6.1.
0