Search Results (5270 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2014-8561 2 Debian, Imagemagick 2 Debian Linux, Imagemagick 2024-11-21 6.5 Medium
imagemagick 6.8.9.6 has remote DOS via infinite loop
CVE-2014-3648 1 Redhat 1 Jboss Aerogear 2024-11-21 7.5 High
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generate endless exceptions when those endpoints can't be reached or can slow the server down by purposefully wasting it's time with slow endpoints. Similarly, one can provide whatever HTTP end point they want. This turns the server into a DDOS vector or an anonymizer for the posting of malware and so on.
CVE-2014-3447 1 Bss Continuity Cms Project 1 Bss Continuty Cms 2024-11-21 7.5 High
BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability
CVE-2014-2885 1 Truecrypt Project 1 Truecrypt 2024-11-21 N/A
Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLength value in the MainThreadProc function in EncryptedIoQueue.c or (2) cause a denial of service (memory consumption) via vectors involving large StartingOffset and Length values in the ProcessVolumeDeviceControlIrp function in Ntdriver.c.
CVE-2014-125066 1 Yuko-bot Project 1 Yuko-bot 2024-11-21 4.3 Medium
A vulnerability was found in emmflo yuko-bot. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument title leads to denial of service. The attack can be initiated remotely. The name of the patch is e580584b877934a4298d4dd0c497c79e579380d0. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217636.
CVE-2014-125036 1 Ansible-ntp Project 1 Ansible-ntp 2024-11-21 2.6 Low
A vulnerability, which was classified as problematic, has been found in drybjed ansible-ntp. Affected by this issue is some unknown functionality of the file meta/main.yml. The manipulation leads to insufficient control of network message volume. The attack can only be done within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. The patch is identified as ed4ca2cf012677973c220cdba36b5c60bfa0260b. It is recommended to apply a patch to fix this issue. VDB-217190 is the identifier assigned to this vulnerability.
CVE-2014-10077 2 Debian, I18n Project 2 Debian Linux, I18n 2024-11-21 N/A
Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.
CVE-2014-10064 1 Qs Project 1 Qs 2024-11-21 N/A
The qs module before 1.0.0 does not have an option or default for specifying object depth and when parsing a string representing a deeply nested object will block the event loop for long periods of time. An attacker could leverage this to cause a temporary denial-of-service condition, for example, in a web application, other requests would not be processed while this blocking is occurring.
CVE-2014-0212 1 Apache 1 Qpid-cpp 2024-11-21 7.5 High
qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors
CVE-2014-0084 1 Redhat 2 Openshift, Openshift Origin 2024-11-21 5.5 Medium
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly.
CVE-2013-7470 1 Linux 1 Linux Kernel 2024-11-21 N/A
cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310.
CVE-2013-4602 1 Avira 10 Antivir Mailgate, Antivir Mailgate Suite, Antivir Personal and 7 more 2024-11-21 5.5 Medium
A Denial of Service (infinite loop) vulnerability exists in Avira AntiVir Engine before 8.2.12.58 via an unspecified function in the PDF Scanner Engine.
CVE-2013-4175 1 Mysecureshell Project 1 Mysecureshell 2024-11-21 5.5 Medium
MySecureShell 1.31 has a Local Denial of Service Vulnerability
CVE-2013-4133 2 Debian, Kde 2 Debian Linux, Kde-workspace 2024-11-21 7.5 High
kde-workspace before 4.10.5 has a memory leak in plasma desktop
CVE-2013-4120 1 Theforeman 1 Katello 2024-11-21 7.5 High
Katello has a Denial of Service vulnerability in API OAuth authentication
CVE-2013-3691 1 Ovislink 2 Airlive Poe2600hd, Airlive Poe2600hd Firmware 2024-11-21 7.5 High
AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL.
CVE-2013-3074 1 Netgear 2 Wndr4700, Wndr4700 Firmware 2024-11-21 7.5 High
NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash).
CVE-2013-20004 1 Starwindsoftware 1 Iscsi San 2024-11-21 9.8 Critical
A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of service state by trying to connect a non-existent target multiple times. This affects iSCSI SAN (Windows Native) Version 6.0, build 2013-01-16.
CVE-2013-1753 2 Python, Redhat 3 Python, Enterprise Linux, Rhel Software Collections 2024-11-21 7.5 High
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
CVE-2013-1055 1 Canonical 2 Ubuntu Linux, Unity-firefox-extension 2024-11-21 4.3 Medium
The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher and updating it with new callbacks until the libunity-webapps rate limit was hit. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 of unity-firefox-extension and in all versions of libunity-webapps by shipping an empty unity-firefox-extension package, thus disabling the extension entirely and invalidating the attack against the libunity-webapps package.