|
283491
|
- |
|
xen
|
xen
|
Xen 4.4.x does not properly validate the load address for 64-bit ARM guest kernels, which allows local users to read system memory or cause a denial of service (crash) via a crafted kernel, which tri…
|
CWE-20
Improper Input Validation
|
CVE-2014-3717
|
2024-11-21 11:08 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283492
|
- |
|
xen
|
xen
|
Xen 4.4.x does not properly check alignment, which allows local users to cause a denial of service (crash) via an unspecified field in a DTB header in a 32-bit guest kernel.
|
CWE-20
Improper Input Validation
|
CVE-2014-3716
|
2024-11-21 11:08 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283493
|
- |
|
xen
|
xen
|
Buffer overflow in Xen 4.4.x allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit guest kernel, related to searching for an appended DTB.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3715
|
2024-11-21 11:08 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283494
|
- |
|
xen
|
xen
|
The ARM image loading functionality in Xen 4.4.x does not properly validate kernel length, which allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit ARM…
|
CWE-20
Improper Input Validation
|
CVE-2014-3714
|
2024-11-21 11:08 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283495
|
- |
|
juniper
|
network_and_security_manager_software nsm3000 nsmexpress
|
Unspecified vulnerability in the NSM XDB service in Juniper NSM before 2012.2R8 allows remote attackers to execute arbitrary code via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2014-3411
|
2024-11-21 11:08 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283496
|
- |
|
flag_module_project
|
flag
|
Eval injection vulnerability in the flag_import_form_validate function in includes/flag.export.inc in the Flag module 7.x-3.0, 7.x-3.5, and earlier for Drupal allows remote authenticated administrato…
|
CWE-94
Code Injection
|
CVE-2014-3453
|
2024-11-21 11:08 |
2014-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283497
|
- |
|
spumko_project
|
hapi_server_framework
|
The hapi server framework 2.0.x and 2.1.x before 2.2.0 for Node.js allows remote attackers to cause a denial of service (file descriptor consumption and process crash) via unspecified vectors.
|
CWE-399
Resource Management Errors
|
CVE-2014-3742
|
2024-11-21 11:08 |
2014-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283498
|
- |
|
canonical djangoproject opensuse debian
|
ubuntu_linux django opensuse debian_linux
|
The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to condu…
|
CWE-20
Improper Input Validation
|
CVE-2014-3730
|
2024-11-21 11:08 |
2014-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283499
|
- |
|
codecguide
|
k-lite_codec_pack
|
Filters\LAV\avfilter-lav-4.dll in K-lite Codec 10.4.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .jpg file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3452
|
2024-11-21 11:08 |
2014-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283500
|
- |
|
dlink
|
dap_1150_firmware dap_1150
|
Cross-site scripting (XSS) vulnerability in D-Link DAP 1150 with firmware 1.2.94 allows remote attackers to inject arbitrary web script or HTML via the res_buf parameter to index.cgi in the Control/U…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3761
|
2024-11-21 11:08 |
2014-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|