mageia records
22 published records for vendor mageia.
Researcher profile
- Entered KEV
- 2 · 9.1%
- Weaponized
- 3 · 13.6%
- Pre-auth RCE
- 4
- With a fix record
- 95.5%
- Median publish → KEV
- 2683 days
Recurring classes
- CWE-399 Resource Management Errors5
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
43Plan | CVE-2014-3566Weaponized | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for manopenssl · openssl · CWE-310 | Low3.4 | — | 100.0% | Oct 14, 2014 |
32Monitor | CVE-2014-9087No exploit | Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of segnupg · libksba · CWE-191 | High7.5 | — | 5.7% | Dec 1, 2014 |
31Monitor | CVE-2013-4159No exploit | ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp fiopensuse · opensuse · CWE-264 | High7.5 | — | 2.4% | Aug 6, 2014 |
28Monitor | CVE-2014-3429No exploit | IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute aripython · ipython notebook · CWE-94 | Medium6.8 | — | 4.7% | Aug 7, 2014 |
28Monitor | CVE-2014-8104No exploit | OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service openvpn · openvpn · CWE-399 | Medium6.8 | — | 3.5% | Dec 3, 2014 |
24Monitor | CVE-2014-5461No exploit | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial lua · lua · CWE-119 | Medium5.0 | — | 11.7% | Sep 4, 2014 |
23Monitor | CVE-2014-9116No exploit | The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote amutt · mutt · CWE-119 | Medium5.0 | — | 9.7% | Dec 2, 2014 |
23Monitor | CVE-2014-9637No exploit | GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted dgnu · patch · CWE-399 | Medium5.5 | — | 2.4% | Aug 25, 2017 |
22Monitor | CVE-2014-8117No exploit | softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumptifile project · file · CWE-399 | Medium5.0 | — | 5.9% | Dec 17, 2014 |
21Monitor | CVE-2015-2189No exploit | Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x befwireshark · wireshark · CWE-189 | Medium5.0 | — | 4.6% | Mar 7, 2015 |
21Monitor | CVE-2014-8116No exploit | The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large nfile project · file · CWE-399 | Medium5.0 | — | 4.4% | Dec 17, 2014 |
21Monitor | CVE-2015-2188No exploit | epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize awireshark · wireshark · CWE-19 | Medium5.0 | — | 4.4% | Mar 7, 2015 |
21Monitor | CVE-2014-7204No exploit | jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a cracanonical · ubuntu linux · CWE-399 | Medium5.0 | — | 4.3% | Oct 7, 2014 |
21Monitor | CVE-2015-2191No exploit | Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and wireshark · wireshark · CWE-189 | Medium5.0 | — | 3.9% | Mar 7, 2015 |
21Monitor | CVE-2014-1829No exploit | Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirepython · requests · CWE-200 | Medium5.0 | — | 2.2% | Oct 15, 2014 |
18Monitor | CVE-2014-9253No exploit | The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers dokuwiki · dokuwiki · CWE-79 | Medium4.3 | — | 2.4% | Dec 17, 2014 |
15Monitor | CVE-2015-0236No exploit | libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1)mageia · mageia · CWE-200 | Low3.5 | — | 1.8% | Jan 29, 2015 |
13Monitor | CVE-2014-2524No exploit | The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlinkgnu · readline · CWE-59 | Low3.3 | — | 0.4% | Aug 20, 2014 |
8Monitor | CVE-2014-3532No exploit | dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service linux · linux kernel · CWE-20 | Low2.1 | — | 0.4% | Jul 19, 2014 |
8Monitor | CVE-2014-8136No exploit | The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when amageia · mageia · CWE-264 | Low2.1 | — | 0.4% | Dec 19, 2014 |
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2014-356643Plan
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man
LowCVSS 3.4WeaponizedEPSS 100%openssl · opensslOct 14, 2014
- CVE-2014-908732Monitor
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of se
HighCVSS 7.5No exploitEPSS 6%gnupg · libksbaDec 1, 2014
- CVE-2013-415931Monitor
ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp fi
HighCVSS 7.5No exploitEPSS 2%opensuse · opensuseAug 6, 2014
- CVE-2014-342928Monitor
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute ar
MediumCVSS 6.8No exploitEPSS 5%ipython · ipython notebookAug 7, 2014
- CVE-2014-810428Monitor
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service
MediumCVSS 6.8No exploitEPSS 3%openvpn · openvpnDec 3, 2014
- CVE-2014-546124Monitor
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial
MediumCVSS 5.0No exploitEPSS 12%lua · luaSep 4, 2014
- CVE-2014-911623Monitor
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote a
MediumCVSS 5.0No exploitEPSS 10%mutt · muttDec 2, 2014
- CVE-2014-963723Monitor
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted d
MediumCVSS 5.5No exploitEPSS 2%gnu · patchAug 25, 2017
- CVE-2014-811722Monitor
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumpti
MediumCVSS 5.0No exploitEPSS 6%file project · fileDec 17, 2014
- CVE-2015-218921Monitor
Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x bef
MediumCVSS 5.0No exploitEPSS 5%wireshark · wiresharkMar 7, 2015
- CVE-2014-811621Monitor
The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large n
MediumCVSS 5.0No exploitEPSS 4%file project · fileDec 17, 2014
- CVE-2015-218821Monitor
epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a
MediumCVSS 5.0No exploitEPSS 4%wireshark · wiresharkMar 7, 2015
- CVE-2014-720421Monitor
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a cra
MediumCVSS 5.0No exploitEPSS 4%canonical · ubuntu linuxOct 7, 2014
- CVE-2015-219121Monitor
Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and
MediumCVSS 5.0No exploitEPSS 4%wireshark · wiresharkMar 7, 2015
- CVE-2014-182921Monitor
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redire
MediumCVSS 5.0No exploitEPSS 2%python · requestsOct 15, 2014
- CVE-2014-925318Monitor
The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers
MediumCVSS 4.3No exploitEPSS 2%dokuwiki · dokuwikiDec 17, 2014
- CVE-2015-023615Monitor
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1)
LowCVSS 3.5No exploitEPSS 2%mageia · mageiaJan 29, 2015
- CVE-2014-252413Monitor
The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink
LowCVSS 3.3No exploitEPSS 0%gnu · readlineAug 20, 2014
- CVE-2014-35328Monitor
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service
LowCVSS 2.1No exploitEPSS 0%linux · linux kernelJul 19, 2014
- CVE-2014-81368Monitor
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when a
LowCVSS 2.1No exploitEPSS 0%mageia · mageiaDec 19, 2014