Vulnerabilities > Mageia > Medium

DATE CVE VULNERABILITY TITLE RISK
2014-12-17 CVE-2014-8117 Resource Management Errors vulnerability in multiple products
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
network
low complexity
file-project freebsd mageia canonical CWE-399
5.0
2014-12-17 CVE-2014-8116 Resource Management Errors vulnerability in multiple products
The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.
network
low complexity
file-project freebsd mageia canonical CWE-399
5.0
2014-12-17 CVE-2014-9253 Cross-Site Scripting vulnerability in multiple products
The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers to execute arbitrary web script or HTML by uploading an SWF file, then accessing it via the media parameter to lib/exe/fetch.php.
4.3
2014-12-03 CVE-2014-8104 Resource Management Errors vulnerability in multiple products
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.
network
low complexity
mageia debian opensuse openvpn canonical CWE-399
6.8
2014-12-02 CVE-2014-9116 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.
network
low complexity
suse mutt debian mageia CWE-119
5.0
2014-10-15 CVE-2014-1829 Information Exposure vulnerability in multiple products
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
network
low complexity
debian python canonical mageia CWE-200
5.0
2014-10-07 CVE-2014-7204 Resource Management Errors vulnerability in multiple products
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
network
low complexity
canonical debian mageia CWE-399
5.0
2014-08-07 CVE-2014-3429 Code Injection vulnerability in multiple products
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.
6.8