|
281211
|
- |
|
apache
|
poi
|
Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) atta…
|
NVD-CWE-Other
|
CVE-2014-3574
|
2024-11-21 11:08 |
2014-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281212
|
- |
|
apache
|
poi
|
The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference…
|
NVD-CWE-Other
|
CVE-2014-3529
|
2024-11-21 11:08 |
2014-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281213
|
- |
|
opensuse suse canonical linux
|
evergreen linux_enterprise_server linux_enterprise_real_time_extension suse_linux_enterprise_server ubuntu_linux linux_kernel
|
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) …
|
CWE-189
Numeric Errors
|
CVE-2014-3601
|
2024-11-21 11:08 |
2014-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281214
|
- |
|
apache
|
axis
|
The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certif…
|
NVD-CWE-Other
|
CVE-2014-3596
|
2024-11-21 11:08 |
2014-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281215
|
- |
|
redhat apache libreoffice
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server openoffice libreoffice
|
The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects.
|
CWE-200
Information Exposure
|
CVE-2014-3575
|
2024-11-21 11:08 |
2014-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281216
|
- |
|
apache libreoffice
|
openoffice libreoffice
|
Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.
|
CWE-77
Command Injection
|
CVE-2014-3524
|
2024-11-21 11:08 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281217
|
- |
|
python debian opensuse
|
pillow python-imaging opensuse
|
PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.
|
CWE-20
Improper Input Validation
|
CVE-2014-3589
|
2024-11-21 11:08 |
2014-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281218
|
- |
|
php
|
php
|
Multiple buffer overflows in the php_parserr function in ext/standard/dns.c in PHP before 5.4.32 and 5.5.x before 5.5.16 allow remote DNS servers to cause a denial of service (application crash) or p…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3597
|
2024-11-21 11:08 |
2014-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281219
|
- |
|
christos_zoulas php
|
file php
|
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause…
|
CWE-189
Numeric Errors
|
CVE-2014-3587
|
2024-11-21 11:08 |
2014-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281220
|
- |
|
saltstack
|
salt
|
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-s…
|
CWE-59
Link Following
|
CVE-2014-3563
|
2024-11-21 11:08 |
2014-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|