Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2015-2296
Disclosure Date: March 18, 2015 (last updated October 05, 2023)
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
0
Attacker Value
Unknown
CVE-2014-8116
Disclosure Date: December 17, 2014 (last updated October 05, 2023)
The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.
0
Attacker Value
Unknown
CVE-2014-8117
Disclosure Date: December 17, 2014 (last updated October 05, 2023)
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-9274
Disclosure Date: December 09, 2014 (last updated October 05, 2023)
UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999".
0
Attacker Value
Unknown
CVE-2014-9037
Disclosure Date: November 25, 2014 (last updated October 05, 2023)
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.
0
Attacker Value
Unknown
CVE-2014-9039
Disclosure Date: November 25, 2014 (last updated October 05, 2023)
wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.
0
Attacker Value
Unknown
CVE-2014-7824
Disclosure Date: November 18, 2014 (last updated December 28, 2023)
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
0
Attacker Value
Unknown
CVE-2014-8763
Disclosure Date: October 22, 2014 (last updated October 05, 2023)
DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password starting with a null (\0) character and a valid user name, which triggers an unauthenticated bind.
0
Attacker Value
Unknown
CVE-2014-8764
Disclosure Date: October 22, 2014 (last updated October 05, 2023)
DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user name and password starting with a null (\0) character, which triggers an anonymous bind.
0
Attacker Value
Unknown
CVE-2013-4159
Disclosure Date: August 06, 2014 (last updated October 05, 2023)
ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp file vulnerabilities" in (1) tcp/tcp_connect.c, (2) server/eventscript.c, (3) tools/ctdb_diagnostics, (4) config/gdb_backtrace, and (5) include/ctdb_private.h.
0