Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2014-05-22 CVE-2014-1770 Resource Management Errors vulnerability in Microsoft Internet Explorer
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::CreateInitialMarkup function.
network
microsoft CWE-399
critical
9.3
2014-05-21 CVE-2012-1166 OS Command Injection vulnerability in Canonical Ltsp Display Manager and Ubuntu Linux
The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.
network
low complexity
canonical CWE-78
critical
10.0
2014-05-20 CVE-2014-3791 Buffer Errors vulnerability in Efssoft Easy File Sharing web Server 6.8
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code via a long string in a cookie UserID parameter to vfolder.ghp.
network
low complexity
efssoft CWE-119
critical
10.0
2014-05-20 CVE-2014-3412 Remote Code Execution vulnerability in Juniper products
Unspecified vulnerability in Juniper Junos Space before 13.3R1.8, when the firewall in disabled, allows remote attackers to execute arbitrary commands via unspecified vectors.
network
low complexity
juniper
critical
10.0
2014-05-20 CVE-2013-7383 Permissions, Privileges, and Access Controls vulnerability in X2Go Server
x2gocleansessions in X2Go Server before 4.0.0.8 and 4.0.1.x before 4.0.1.10 allows remote authenticated users to gain privileges via unspecified vectors, possibly related to backticks.
network
low complexity
x2go CWE-264
critical
9.0
2014-05-20 CVE-2014-3444 Code Injection vulnerability in Realnetworks Realplayer
The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write access violation and application crash) via a malformed .3gp file.
network
realnetworks CWE-94
critical
9.3
2014-05-19 CVE-2014-3411 Remote Code Execution vulnerability in Juniper products
Unspecified vulnerability in the NSM XDB service in Juniper NSM before 2012.2R8 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
juniper
critical
10.0
2014-05-16 CVE-2014-0749 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adaptivecomputing Torque Resource Manager
Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x through 2.5.13 allows remote attackers to execute arbitrary code via a large count value.
network
low complexity
adaptivecomputing CWE-119
critical
10.0
2014-05-15 CVE-2013-4730 Buffer Errors vulnerability in Pcman'S FTP Server Project Pcman'S FTP Server 2.0.7
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USER command.
network
low complexity
pcman-s-ftp-server-project CWE-119
critical
10.0
2014-05-14 CVE-2014-1815 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Internet Explorer
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as exploited in the wild in May 2014, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0310.
network
microsoft CWE-119
critical
9.3