Latest CVE Feed
-
5.3
MEDIUMCVE-2014-8328
The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request.... Read more
Affected Products : dynamic_content_elements- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-8322
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.... Read more
Affected Products : aircrack-ng- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-8321
Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local users to execute arbitrary code or gain privileges via unspecified vectors.... Read more
Affected Products : aircrack-ng- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2014-8271
Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain privileges via a long variable name.... Read more
Affected Products : edk2- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-8184
A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or p... Read more
Affected Products : liblouis- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2014-8183
It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.... Read more
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-8182
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.... Read more
- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-8181
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.... Read more
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-8179
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-dig... Read more
- Published: Dec. 17, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-8178
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.... Read more
- Published: Dec. 17, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-8171
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.... Read more
- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2014-8167
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack... Read more
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-8166
The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.... Read more
Affected Products : cups- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2014-8164
A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.... Read more
Affected Products : cloudforms_management_engine- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-8161
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-8141
Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.... Read more
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-8140
Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.... Read more
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-8139
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.... Read more
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2014-8130
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanli... Read more
- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-8129
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_... Read more
- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024