Latest CVE Feed
-
6.4
MEDIUMCVE-2014-9351
engine/server/server.cpp in Teeworlds 0.6.x before 0.6.3 allows remote attackers to read memory and cause a denial of service (crash) via unspecified vectors.... Read more
Affected Products : teeworlds- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9319
The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted .bit file.... Read more
Affected Products : ffmpeg- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9318
The raw_decode function in libavcodec/rawdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap access) and possibly have other unspecified impact via a crafted .c... Read more
Affected Products : ffmpeg- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9317
The decode_ihdr_chunk function in libavcodec/pngdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap access) and possibly have other unspecified impact via an ID... Read more
Affected Products : ffmpeg- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9316
The mjpeg_decode_app function in libavcodec/mjpegdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap access) and possibly have other unspecified impact via vect... Read more
Affected Products : ffmpeg- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9281
Cross-site scripting (XSS) vulnerability in admin/copy_field.php in MantisBT before 1.2.18 allows remote attackers to inject arbitrary web script or HTML via the dest_id field.... Read more
Affected Products : mantisbt- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9275
UnRTF allows remote attackers to cause a denial of service (out-of-bounds memory access and crash) and possibly execute arbitrary code via a crafted RTF file.... Read more
Affected Products : unrtf- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9274
UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999".... Read more
- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
4.7
MEDIUMCVE-2014-9066
Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requ... Read more
- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
4.4
MEDIUMCVE-2014-9065
common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a differen... Read more
- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2014-8737
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or fu... Read more
- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-8504
Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.... Read more
- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-8503
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.... Read more
- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-8502
Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a truncated export table in a PE file.... Read more
- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-8501
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the A... Read more
- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-8485
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.... Read more
- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-8484
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.... Read more
- Published: Dec. 09, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9350
TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of service (httpd crash) via vectors involving a "new" value in the isNew parameter to PingIframeRpm.htm.... Read more
- Published: Dec. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9349
Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) nom or (2) user_agent parameter to admin/robots.php.... Read more
Affected Products : robotstats- Published: Dec. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9348
SQL injection vulnerability in the formulaireRobot function in admin/robots.lib.php in RobotStats 1.0 allows remote attackers to execute arbitrary SQL commands via the robot parameter to admin/robots.php.... Read more
Affected Products : robotstats- Published: Dec. 08, 2014
- Modified: Apr. 12, 2025