Vulnerabilities > Code

DATE CVE VULNERABILITY TITLE RISK
2014-12-24 CVE-2014-9222 Code vulnerability in Allegrosoft Rompager 4.07
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.
network
low complexity
allegrosoft CWE-17
critical
10.0
2014-12-20 CVE-2014-9296 Code vulnerability in NTP
The receive function in ntp_proto.c in ntpd in NTP before 4.2.8 continues to execute after detecting a certain authentication error, which might allow remote attackers to trigger an unintended association change via crafted packets.
network
low complexity
ntp CWE-17
5.0
2014-12-09 CVE-2014-9066 Code vulnerability in multiple products
Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065.
4.7
2014-12-09 CVE-2014-9065 Code vulnerability in multiple products
common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability to CVE-2014-9066.
4.4
2014-12-05 CVE-2014-9143 Code vulnerability in Technicolor Td5130 Router Firmware 2.05.C29Gv
Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the failrefer parameter.
4.3
2014-12-02 CVE-2013-6494 Code vulnerability in Fedup Project Fedup 0.9.0
fedup 0.9.0 in Fedora 19, 20, and 21 uses a temporary directory with a static name for its download cache, which allows local users to cause a denial of service (prevention of system updates).
local
low complexity
fedup-project fedoraproject CWE-17
2.1
2014-12-01 CVE-2014-8867 Code vulnerability in multiple products
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.
local
low complexity
redhat xen debian opensuse CWE-17
4.9
2014-12-01 CVE-2014-8866 Code vulnerability in multiple products
The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a 64-bit hypervisor, allows local 32-bit HVM guests to cause a denial of service (host crash) via vectors involving altering the high halves of registers while in 64-bit mode.
4.7
2014-12-01 CVE-2013-6497 Code vulnerability in Clamav
clamscan in ClamAV before 0.98.5, when using -a option, allows remote attackers to cause a denial of service (crash) as demonstrated by the jwplayer.js file.
local
low complexity
clamav CWE-17
2.1
2014-11-27 CVE-2014-5426 Code vulnerability in Matrikonopc Dnp3 OPC Server 1.2.3
MatrikonOPC OPC Server for DNP3 1.2.3 and earlier allows remote attackers to cause a denial of service (unhandled exception and DNP3 process crash) via a crafted message.
network
low complexity
matrikonopc CWE-17
5.0