|
278601
|
- |
|
linux suse canonical redhat
|
linux_kernel linux_enterprise_server ubuntu_linux enterprise_linux_server_aus enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_eus
|
Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2014-4656
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278602
|
- |
|
linux suse canonical
|
linux_kernel linux_enterprise_server ubuntu_linux
|
The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local user…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2014-4655
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278603
|
- |
|
linux suse canonical
|
linux_kernel linux_enterprise_server ubuntu_linux
|
The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, whic…
|
CWE-416
Use After Free
|
CVE-2014-4654
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278604
|
- |
|
linux suse canonical
|
linux_kernel linux_enterprise_server ubuntu_linux
|
sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-a…
|
CWE-416
Use After Free
|
CVE-2014-4653
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278605
|
- |
|
linux suse canonical redhat
|
linux_kernel linux_enterprise_server ubuntu_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users t…
|
CWE-362
Race Condition
|
CVE-2014-4652
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278606
|
- |
|
linux
|
linux_kernel
|
Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bi…
|
CWE-20
Improper Input Validation
|
CVE-2014-4611
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278607
|
- |
|
linux suse opensuse canonical
|
linux_kernel linux_enterprise_real_time_extension opensuse linux_enterprise_server ubuntu_linux
|
Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to caus…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2014-4608
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278608
|
- |
|
piwigo
|
piwigo
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Piwigo before 2.6.2 allow remote attackers to hijack the authentication of administrators for requests that use the (1) pwg.groups.addUse…
|
CWE-352
Origin Validation Error
|
CVE-2014-4614
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278609
|
- |
|
zeenshare_project
|
zeenshare
|
Cross-site scripting (XSS) vulnerability in redirect_to_zeenshare.php in the ZeenShare plugin 1.0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the zs…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4606
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278610
|
- |
|
wp_social_invitations_project
|
wp_social_invitations
|
Cross-site scripting (XSS) vulnerability in test.php in the WP Social Invitations plugin before 1.4.4.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xhrurl par…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4597
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|