LiveActive security incident?Get immediate response
CVE archive

October 2014

Browse CVE records published in October 2014, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1439 matching CVEs · Page 4 of 29.

Unknown · CVSS Not scored

CVE-2014-7975: The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMI...

The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.

Published Oct 13, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7784: The Schon!

The Schon! Magazine (aka com.magzter.schonmagazine) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Published Oct 21, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-7783: The Bill G.

The Bill G. Bennett (aka com.billgbennett) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Published Oct 21, 2014 · Updated Aug 6, 2024