|
283881
|
- |
|
apple todd_miller
|
mac_os_x sudo
|
Sudo 1.6.9 before 1.8.5, when env_reset is disabled, does not properly check environment variables for the env_delete restriction, which allows local users with sudo permissions to bypass intended co…
|
CWE-20
Improper Input Validation
|
CVE-2014-0106
|
2024-11-21 11:01 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283882
|
- |
|
freedesktop canonical
|
udisks ubuntu_linux
|
Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-0004
|
2024-11-21 11:01 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283883
|
- |
|
linux
|
linux_kernel
|
The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not properly determine whether keyrings are identical, which allows local users to cause …
|
CWE-310
Cryptographic Issues
|
CVE-2014-0102
|
2024-11-21 11:01 |
2014-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283884
|
- |
|
linux
|
linux_kernel
|
Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of service (use-after-free error) or possibly …
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2014-0100
|
2024-11-21 11:01 |
2014-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283885
|
- |
|
linux redhat canonical f5
|
linux_kernel enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_eus ubuntu_lin…
|
The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call,…
|
CWE-476
NULL Pointer Dereference
|
CVE-2014-0101
|
2024-11-21 11:01 |
2014-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283886
|
- |
|
linux
|
linux_kernel
|
Buffer overflow in the complete_emulated_mmio function in arch/x86/kvm/x86.c in the Linux kernel before 3.13.6 allows guest OS users to execute arbitrary code on the host OS by leveraging a loop that…
|
CWE-120
Classic Buffer Overflow
|
CVE-2014-0049
|
2024-11-21 11:01 |
2014-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283887
|
- |
|
apache
|
struts
|
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
|
NVD-CWE-noinfo
|
CVE-2014-0094
|
2024-11-21 11:01 |
2014-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283888
|
- |
|
gnu
|
gnutls
|
lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attack…
|
CWE-310
Cryptographic Issues
|
CVE-2014-0092
|
2024-11-21 11:01 |
2014-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283889
|
- |
|
serena
|
dimensions_cm
|
Cross-site request forgery (CSRF) vulnerability in the web client in Serena Dimensions CM 12.2 build 7.199.0 allows remote attackers to hijack the authentication of administrators for requests that u…
|
CWE-352
Origin Validation Error
|
CVE-2014-0336
|
2024-11-21 11:01 |
2014-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283890
|
- |
|
serena
|
dimensions_cm
|
Multiple cross-site scripting (XSS) vulnerabilities in the web client in Serena Dimensions CM 12.2 build 7.199.0 allow remote attackers to inject arbitrary web script or HTML via the (1) DB_CONN, (2)…
|
CWE-79
Cross-site Scripting
|
CVE-2014-0335
|
2024-11-21 11:01 |
2014-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|