|
278471
|
6.1 |
MEDIUM
Local
|
linux
|
linux_kernel
|
fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allows local users to bypass intended access restr…
|
CWE-284
Improper Access Control
|
CVE-2014-9717
|
2024-11-21 11:21 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278472
|
3.3 |
LOW
Local
|
opensuse
|
opensuse
|
tmpfiles.d/systemd.conf in systemd before 214 uses weak permissions for journal files under (1) /run/log/journal/%m and (2) /var/log/journal/%m, which allows local users to obtain sensitive informati…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9770
|
2024-11-21 11:21 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278473
|
8.8 |
HIGH
Network
|
canonical debian xdelta opensuse
|
ubuntu_linux debian_linux xdelta3 opensuse
|
Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9765
|
2024-11-21 11:21 |
2016-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278474
|
9.8 |
CRITICAL
Network
|
suse opensuse fedoraproject gnu canonical
|
linux_enterprise_server linux_enterprise_debuginfo linux_enterprise_software_development_kit linux_enterprise_desktop opensuse suse_linux_enterprise_server fedora glibc ubuntu…
|
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9761
|
2024-11-21 11:21 |
2016-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278475
|
6.5 |
MEDIUM
Network
|
debian remotesensing
|
debian_linux libtiff
|
The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9655
|
2024-11-21 11:21 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278476
|
9.8 |
CRITICAL
Network
|
pixman canonical
|
pixman ubuntu_linux
|
Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code…
|
CWE-189
Numeric Errors
|
CVE-2014-9766
|
2024-11-21 11:21 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278477
|
5.3 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obtain sensitive master salt configuration information…
|
CWE-200
Information Exposure
|
CVE-2014-9759
|
2024-11-21 11:21 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278478
|
7.3 |
HIGH
Network
|
pcre
|
pcre
|
pcre_jit_compile.c in PCRE 8.35 does not properly use table jumps to optimize nested alternatives, which allows remote attackers to cause a denial of service (stack memory corruption) or possibly hav…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9769
|
2024-11-21 11:21 |
2016-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278479
|
8.8 |
HIGH
Network
|
ibm
|
tivoli_netview_access_services
|
IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9768
|
2024-11-21 11:21 |
2016-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278480
|
9.8 |
CRITICAL
Network
|
atlassian
|
bamboo
|
The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an X…
|
CWE-20
Improper Input Validation
|
CVE-2014-9757
|
2024-11-21 11:21 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|