Latest CVE Feed
-
7.8
HIGHCVE-2014-8141
Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.... Read more
- EPSS Score: %9.81
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-8140
Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.... Read more
- EPSS Score: %9.81
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-8139
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.... Read more
- EPSS Score: %9.81
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2014-8130
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanli... Read more
- EPSS Score: %2.08
- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-8129
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_... Read more
- EPSS Score: %0.82
- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2014-8128
LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image.... Read more
- EPSS Score: %0.70
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-8126
The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.... Read more
Affected Products : htcondor- EPSS Score: %1.45
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-8089
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.... Read more
- EPSS Score: %1.12
- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-7952
The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter application data streams.... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2014-7951
Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a direct connection to the target Android device to write to arbitrary files owned by system via a .. (dot dot) in the tar ... Read more
Affected Products : android- EPSS Score: %1.96
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2014-7914
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Feb. 21, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-7863
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and re... Read more
- EPSS Score: %88.87
- Published: Feb. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-7862
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.... Read more
Affected Products : desktop_central- EPSS Score: %81.40
- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-7844
BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.... Read more
- EPSS Score: %0.91
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-7303
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading etc/dbdump.db.... Read more
Affected Products : sgi_tempo- EPSS Score: %0.05
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-7302
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx.... Read more
Affected Products : sgi_tempo- EPSS Score: %0.06
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2014-7301
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /etc/odapw.... Read more
Affected Products : sgi_tempo- EPSS Score: %0.12
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-7272
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the ... Read more
- EPSS Score: %0.15
- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-7271
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.... Read more
- EPSS Score: %0.09
- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-7257
SQL injection vulnerability in DBD::PgPP 0.05 and earlier... Read more
Affected Products : \- EPSS Score: %0.31
- Published: Dec. 11, 2019
- Modified: Nov. 21, 2024