Skip to content
Noroxi

mageia records

22 published records for vendor mageia.

All records

22 records
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man

    LowCVSS 3.4WeaponizedEPSS 100%

    openssl · opensslOct 14, 2014

  • CVE-2014-9087
    32Monitor

    Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of se

    HighCVSS 7.5No exploitEPSS 6%

    gnupg · libksbaDec 1, 2014

  • CVE-2013-4159
    31Monitor

    ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp fi

    HighCVSS 7.5No exploitEPSS 2%

    opensuse · opensuseAug 6, 2014

  • CVE-2014-3429
    28Monitor

    IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute ar

    MediumCVSS 6.8No exploitEPSS 5%

    ipython · ipython notebookAug 7, 2014

  • CVE-2014-8104
    28Monitor

    OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service

    MediumCVSS 6.8No exploitEPSS 3%

    openvpn · openvpnDec 3, 2014

  • CVE-2014-5461
    24Monitor

    Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial

    MediumCVSS 5.0No exploitEPSS 12%

    lua · luaSep 4, 2014

  • CVE-2014-9116
    23Monitor

    The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote a

    MediumCVSS 5.0No exploitEPSS 10%

    mutt · muttDec 2, 2014

  • CVE-2014-9637
    23Monitor

    GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted d

    MediumCVSS 5.5No exploitEPSS 2%

    gnu · patchAug 25, 2017

  • CVE-2014-8117
    22Monitor

    softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumpti

    MediumCVSS 5.0No exploitEPSS 6%

    file project · fileDec 17, 2014

  • CVE-2015-2189
    21Monitor

    Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x bef

    MediumCVSS 5.0No exploitEPSS 5%

    wireshark · wiresharkMar 7, 2015

  • CVE-2014-8116
    21Monitor

    The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large n

    MediumCVSS 5.0No exploitEPSS 4%

    file project · fileDec 17, 2014

  • CVE-2015-2188
    21Monitor

    epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a

    MediumCVSS 5.0No exploitEPSS 4%

    wireshark · wiresharkMar 7, 2015

  • CVE-2014-7204
    21Monitor

    jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a cra

    MediumCVSS 5.0No exploitEPSS 4%

    canonical · ubuntu linuxOct 7, 2014

  • CVE-2015-2191
    21Monitor

    Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and

    MediumCVSS 5.0No exploitEPSS 4%

    wireshark · wiresharkMar 7, 2015

  • CVE-2014-1829
    21Monitor

    Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redire

    MediumCVSS 5.0No exploitEPSS 2%

    python · requestsOct 15, 2014

  • CVE-2014-9253
    18Monitor

    The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers

    MediumCVSS 4.3No exploitEPSS 2%

    dokuwiki · dokuwikiDec 17, 2014

  • CVE-2015-0236
    15Monitor

    libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1)

    LowCVSS 3.5No exploitEPSS 2%

    mageia · mageiaJan 29, 2015

  • CVE-2014-2524
    13Monitor

    The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink

    LowCVSS 3.3No exploitEPSS 0%

    gnu · readlineAug 20, 2014

  • dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service

    LowCVSS 2.1No exploitEPSS 0%

    linux · linux kernelJul 19, 2014

  • The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when a

    LowCVSS 2.1No exploitEPSS 0%

    mageia · mageiaDec 19, 2014