Latest CVE Feed
-
6.4
MEDIUMCVE-2014-7185
Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-6394
visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" d... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2014-5308
Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name parameter in a Search action to lib/project/projectView.php or (2) id parameter to lib/events/eventinfo.php.... Read more
Affected Products : testlink- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-7967
Multiple unspecified vulnerabilities in Google V8 before 3.28.71.15, as used in Google Chrome before 38.0.2125.101, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3200
Multiple unspecified vulnerabilities in Google Chrome before 38.0.2125.101 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3199
The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 38.0.2125.101, has an erroneous fallback outcome for wrapper-selection failures, which allows remote attackers to cause a denial of... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3198
The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of ... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3197
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attacke... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3196
base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.... Read more
Affected Products : chrome- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3195
Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as allocations of uninitialized memory and does not properly concatenate arrays of double-precision floating-point numbers, which allows r... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3194
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3193
The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that lever... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3192
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of serv... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3191
Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers a widget-position update that im... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3190
Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3189
The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) or poss... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-3188
Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an e... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-3187
Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict processing of (1) facetime:// and (2) facetime-audio:// URLs, which allows remote attackers to obtain video and audio data from a device via a crafted web sit... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-7299
Unspecified vulnerability in administrative interfaces in ArubaOS 6.3.1.11, 6.3.1.11-FIPS, 6.4.2.1, and 6.4.2.1-FIPS on Aruba controllers allows remote attackers to bypass authentication, and obtain potentially sensitive information or add guest accounts,... Read more
Affected Products : arubaos- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2014-7275
The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof POP3 servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : getmail- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025