Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2014-07-23 CVE-2014-1544 Use After Free Memory Corruption vulnerability in Mozilla Firefox/Thunderbird
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.
network
low complexity
mozilla
critical
10.0
2014-07-22 CVE-2014-4947 Buffer Errors vulnerability in Citrix Xenserver 6.2.0
Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.
network
low complexity
citrix CWE-119
critical
10.0
2014-07-20 CVE-2014-1987 OS Command Injection vulnerability in Cybozu Garoon
The CGI component in Cybozu Garoon 3.1.0 through 3.7 SP3 allows remote attackers to execute arbitrary commands via unspecified vectors.
network
low complexity
cybozu CWE-78
critical
10.0
2014-07-18 CVE-2014-3306 Improper Input Validation vulnerability in Cisco products
The web server on Cisco DPC3010, DPC3212, DPC3825, DPC3925, DPQ3925, EPC3010, EPC3212, EPC3825, and EPC3925 Wireless Residential Gateway products allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCup40808.
network
low complexity
cisco CWE-20
critical
10.0
2014-07-18 CVE-2014-2623 Remote Code Execution vulnerability in HP Storage Data Protector 8.0/8.10
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.
network
low complexity
hp
critical
10.0
2014-07-17 CVE-2014-4262 Unspecified vulnerability in Oracle JDK and JRE
Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
network
oracle
critical
9.3
2014-07-17 CVE-2014-4247 Unspecified vulnerability in Oracle JDK and JRE
Unspecified vulnerability in Oracle Java SE 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to JavaFX.
network
oracle
critical
9.3
2014-07-17 CVE-2014-4227 Unspecified vulnerability in Oracle JDK and JRE
Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
network
low complexity
oracle
critical
10.0
2014-07-17 CVE-2014-4223 Unspecified vulnerability in Oracle JDK and JRE
Unspecified vulnerability in Oracle Java SE 7u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-2483.
network
oracle
critical
9.3
2014-07-17 CVE-2014-4219 Unspecified vulnerability in Oracle JDK and JRE
Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
network
oracle
critical
9.3