Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
MEDIUM 5.0
CVE-2014-1565
The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and T…
Firefox
after 31.1.0
MEDIUM 5.0
CVE-2014-3173
The WebGL implementation in Google Chrome before 37.0.2062.94 does not ensure that clear calls interact properly with the state of a draw buffer, whi…
Chrome
after 37.0.2062.93
MEDIUM 5.0
CVE-2014-3174
modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly co…
Chrome
after 37.0.2062.93
MEDIUM 6.8
CVE-2014-5263
vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause…
Qemu
Patch available
HIGH 7.2
CVE-2014-5307
Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 allows local users to gain pri…
Panda Av Pro 2014
No fix yet
MEDIUM 5.0
CVE-2014-5384
The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (out…
FreeBSD
Mitigation only
MEDIUM 5.0
CVE-2014-5349
Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash) via nested…
Spark Browser
No fix yet
MEDIUM 6.8
CVE-2014-1384
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…
Safari
after 6.1.5
MEDIUM 6.8
CVE-2014-1385
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…
Safari
after 6.1.5
MEDIUM 6.8
CVE-2014-1386
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…
Safari
after 6.1.5
MEDIUM 6.8
CVE-2014-1387
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…
Safari
after 6.1.5
MEDIUM 6.8
CVE-2014-1388
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…
Safari
after 6.1.5
MEDIUM 6.8
CVE-2014-1389
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…
Safari
after 6.1.5
MEDIUM 6.8
CVE-2014-1390
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…
Safari
after 6.1.5
HIGH 7.1
CVE-2014-2357
The GPT library in the Telegyr 8979 Master Protocol application in SUBNET SubSTATION Server 2 before SSNET 2.12 HF18808 allows remote attackers to ca…
Substation Server
after 2.12
MEDIUM 6.8
CVE-2014-4647
Stack-based buffer overflow in the loadExtensionFactory method in the TSVisualization ActiveX control in Embarcadero ER/Studio Data Architect allows …
Er\/studio Data Architect
Mitigation only
MEDIUM 6.8
CVE-2014-3459EPSS 12%
Heap-based buffer overflow in SolarWinds Network Configuration Manager (NCM) before 7.3 allows remote attackers to execute arbitrary code via the PEs…
Network Configuration Manager
after 7.2.2
MEDIUM 6.9
CVE-2014-3434
Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition be…
Endpoint Protection
No fix yet
MEDIUM 5.0
CVE-2014-5161
The dissect_log function in plugins/irda/packet-irda.c in the IrDA dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' character…
Wireshark
Mitigation only
MEDIUM 5.0
CVE-2014-5162
The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000 dissector in Wireshark 1.10.x before 1.10.9 does not properly strip …
Wireshark
Mitigation only
MEDIUM 5.0
CVE-2014-5163
The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management dissectors i…
Wireshark
No fix yet
MEDIUM 5.0
CVE-2014-5164
The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.10.x before 1.10.9 initializes a certain structure mem…
Wireshark
No fix yet
MEDIUM 5.0
CVE-2014-5165
The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not …
Wireshark
No fix yet
MEDIUM 5.0
CVE-2014-3488
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hell…
Netty
after 3.9.1.1
HIGH 7.8
CVE-2014-4927EPSS 11%
Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to …
Micro Httpd
No fix yet
HIGH 9.3
CVE-2014-3939EPSS 6%
Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer bitmap data in…
Sketchbook Pro
after 6.2.5
HIGH 10.0
CVE-2014-4501
Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unsp…
Sgminer
after 4.3.4
HIGH 10.0
CVE-2014-4502
Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remo…
Bfgminer
after 4.2.1
HIGH 9.3
CVE-2014-1549EPSS 6%
The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox before 31.0 and Thunderbird before 31.0 does not prope…
Firefox
after 30.0
HIGH 10.0
CVE-2014-4947EPSS 5%
Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.
Xenserver
Mitigation only