|
277501
|
6.5 |
MEDIUM
Network
|
libtiff redhat apple
|
libtiff enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterprise_linux_server_eus mac_os_x…
|
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a craf…
|
CWE-369
Divide By Zero
|
CVE-2014-8130
|
2024-11-21 11:18 |
2018-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277502
|
8.8 |
HIGH
Network
|
libtiff debian redhat apple
|
libtiff debian_linux enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_server enterprise_linux_server_eus mac_os_x iphone_os
|
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c t…
|
CWE-787
Out-of-bounds Write
|
CVE-2014-8129
|
2024-11-21 11:18 |
2018-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277503
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux enterprise_mrg
|
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
|
CWE-399
Resource Management Errors
|
CVE-2014-8171
|
2024-11-21 11:18 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277504
|
8.8 |
HIGH
Network
|
cups
|
cups
|
The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.
|
CWE-20
Improper Input Validation
|
CVE-2014-8166
|
2024-11-21 11:18 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277505
|
7.8 |
HIGH
Local
|
google
|
android
|
The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter application data streams.
|
CWE-74
Injection
|
CVE-2014-7952
|
2024-11-21 11:18 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277506
|
6.5 |
MEDIUM
Network
|
wp-dbmanager_project
|
wp-dbmanager
|
The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attackers to read arbitrary files by leveraging failure to sufficiently limit queries,…
|
CWE-20
Improper Input Validation
|
CVE-2014-8336
|
2024-11-21 11:18 |
2018-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277507
|
7.8 |
HIGH
Local
|
wp-dbmanager_project
|
wp-dbmanager
|
(1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress place credentials on the mysqldump command line, which allows local users…
|
CWE-255
Credentials Management
|
CVE-2014-8335
|
2024-11-21 11:18 |
2018-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277508
|
9.8 |
CRITICAL
Network
|
zohocorp
|
desktop_central
|
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7862
|
2024-11-21 11:18 |
2018-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277509
|
7.5 |
HIGH
Network
|
redhat fedoraproject netcf_project
|
enterprise_linux fedora netcf
|
The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
|
CWE-20
Improper Input Validation
|
CVE-2014-8119
|
2024-11-21 11:18 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277510
|
7.8 |
HIGH
Local
|
huawei
|
ec156_firmware ec176_firmware ec177_firmware
|
Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014) use a weak ACL for the…
|
CWE-426
Untrusted Search Path
|
CVE-2014-8358
|
2024-11-21 11:18 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|