CVE-2014-7145 (enterprise_linux_desktop, enterprise_linux_hpc_node, enterprise_linux_server, enterprise_linux_workstation, linux_kernel, ubuntu_linux)

CVE-2014-7145 (enterprise_linux_desktop, enterprise_linux_hpc_node, enterprise_linux_server, enterprise_linux_workstation, linux_kernel, ubuntu_linux)

The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other impact by deleting the IPC$ share during resolution of DFS referrals.

Source: CVE-2014-7145 (enterprise_linux_desktop, enterprise_linux_hpc_node, enterprise_linux_server, enterprise_linux_workstation, linux_kernel, ubuntu_linux)

CVE-2014-1564 (evergreen, firefox, firefox_esr, opensuse, thunderbird)

CVE-2014-1564 (evergreen, firefox, firefox_esr, opensuse, thunderbird)

Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image.

Source: CVE-2014-1564 (evergreen, firefox, firefox_esr, opensuse, thunderbird)

CVE-2014-1563 (evergreen, firefox, firefox_esr, opensuse, thunderbird)

CVE-2014-1563 (evergreen, firefox, firefox_esr, opensuse, thunderbird)

Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG animation with DOM interaction that triggers incorrect cycle collection.

Source: CVE-2014-1563 (evergreen, firefox, firefox_esr, opensuse, thunderbird)

CVE-2014-1553 (evergreen, firefox, firefox_esr, opensuse, thunderbird)

CVE-2014-1553 (evergreen, firefox, firefox_esr, opensuse, thunderbird)

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Source: CVE-2014-1553 (evergreen, firefox, firefox_esr, opensuse, thunderbird)