|
283621
|
- |
|
linux opensuse
|
linux_kernel opensuse
|
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted tim…
|
CWE-20
Improper Input Validation
|
CVE-2014-0038
|
2024-11-21 11:01 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283622
|
- |
|
pidgin
|
pidgin
|
The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of service (application crash) via a crafted message.
|
CWE-20
Improper Input Validation
|
CVE-2014-0020
|
2024-11-21 11:01 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283623
|
- |
|
dest-unreach fedoraproject opensuse
|
socat fedora opensuse
|
Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CON…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-0019
|
2024-11-21 11:01 |
2014-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283624
|
- |
|
zte
|
zxv10_w300
|
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows remote attackers to obtain administrative access by leveraging k…
|
CWE-255
Credentials Management
|
CVE-2014-0329
|
2024-11-21 11:01 |
2014-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283625
|
- |
|
haxx
|
libcurl curl
|
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via…
|
CWE-287
Improper Authentication
|
CVE-2014-0015
|
2024-11-21 11:01 |
2014-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283626
|
- |
|
mariadb redhat oracle
|
mariadb enterprise_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation mysql
|
Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-0001
|
2024-11-21 11:01 |
2014-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283627
|
- |
|
baseurl
|
yum
|
The installUpdates function in yum-cron/yum-cron.py in yum 3.4.3 and earlier does not properly check the return value of the sigCheckPkg function, which allows remote attackers to bypass the RMP pack…
|
CWE-20
Improper Input Validation
|
CVE-2014-0022
|
2024-11-21 11:01 |
2014-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283628
|
- |
|
cmu
|
flite
|
The play_wave_from_socket function in audio/auserver.c in Flite 1.4 allows local users to modify arbitrary files via a symlink attack on /tmp/awb.wav. NOTE: some of these details are obtained from t…
|
CWE-59
Link Following
|
CVE-2014-0027
|
2024-11-21 11:01 |
2014-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283629
|
- |
|
redhat
|
libvirt
|
libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a reques…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0028
|
2024-11-21 11:01 |
2014-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283630
|
- |
|
openstack
|
swift
|
The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timin…
|
CWE-200
Information Exposure
|
CVE-2014-0006
|
2024-11-21 11:01 |
2014-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|