Search

Found 3,842 results in 357ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2015-8863 critical 9.8 9.8 FIX debian debiansuse suse jq_project 10y ago Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.
CVE-2015-0858 low 3.3 3.3 FIX debian debian tardiff_project 10y ago Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory.
CVE-2015-0857 critical 9.8 9.8 FIX debian debian tardiff_project 10y ago Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.
CVE-2016-3716 low 3.3 4.3 EXPFIX debian debian rhelubuntu ubuntu imagemagick 10y ago The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.
CVE-2016-2108 critical 9.8 9.8 FIX slesdebian debian rhel openssl 10y ago The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via a…
CVE-2015-8812 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu 10y ago drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service …
CVE-2016-4002 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu qemu 10y ago Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of service (memory cor…
CVE-2016-3074 critical 9.8 10.0 EXPFIX slesdebian debiansuse suse libgdphp 10y ago Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed g…
CVE-2016-2785 critical 9.8 9.8 FIX slesdebian debian puppet 10y ago Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveragin…
CVE-2016-4053 low 3.7 3.7 FIX slesubuntu ubuntudebian debian squid-cache 10y ago Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and…
CVE-2016-3443 critical 9.6 9.6 FIX slesdebian debian oracle 10y ago Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D. NOTE: the previous informa…
CVE-2016-3426 low 3.1 3.1 FIX slesdebian debian oracle 10y ago Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.
CVE-2016-0687 critical 9.6 9.6 FIX slesdebian debian oracle 10y ago Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the H…
CVE-2016-0686 critical 9.6 9.6 FIX slesdebian debian oracle 10y ago Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Seria…
CVE-2016-0643 low 3.3 3.3 sles rhelsuse suse ibmoraclemariadb 10y ago Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users…
CVE-2015-8842 low 3.3 3.3 FIX suse susedebian debian 10y ago tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log/journal/%m/system.journal, which allows local users to obtain sensitive information by reading the file.
CVE-2014-9770 low 3.3 3.3 FIX suse susedebian debian 10y ago tmpfiles.d/systemd.conf in systemd before 214 uses weak permissions for journal files under (1) /run/log/journal/%m and (2) /var/log/journal/%m, which allows local users to obtain sensitive informati…
CVE-2015-8779 critical 9.8 9.8 FIX debian debianfedora fedoraubuntu ubuntu susegnu 10y ago Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possib…
CVE-2015-8778 critical 9.8 9.8 FIX debian debianfedora fedoraubuntu ubuntu gnususe 10y ago Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the s…
CVE-2015-8776 critical 9.1 9.1 FIX debian debianfedora fedoraubuntu ubuntu susegnu 10y ago The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive informatio…
CVE-2015-7511 low 2.0 2.0 FIX slesdebian debianubuntu ubuntu gnupg 10y ago Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring elec…
CVE-2014-9761 critical 9.8 9.8 FIX debian debianfedora fedoraubuntu ubuntu susegnu 10y ago Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbi…
CVE-2016-1659 critical 9.8 9.8 debian debianubuntu ubuntususe suse google 10y ago Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-1503 critical 9.8 9.8 FIX slesdebian debian dhcpcd_project 10y ago dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attacke…
CVE-2010-5325 critical 9.8 9.8 FIX slesdebian debian rhel linuxfoundation 10y ago Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly ex…
CVE-2016-4009 critical 9.8 9.8 FIX slesdebian debian python 10y ago Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, whic…
CVE-2016-3159 low 3.8 3.8 FIX slesdebian debianfedora fedora 10y ago The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensiti…
CVE-2016-3158 low 3.8 3.8 FIX fedora fedoradebian debian 10y ago The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive …
CVE-2016-2057 low 3.3 3.3 FIX debian debian xymon 10y ago lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to th…
CVE-2016-2054 critical 9.8 9.8 FIX debian debian xymon 10y ago Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via …
CVE-2015-7545 critical 9.8 9.8 FIX slesdebian debiansuse suse git_projectredhat 10y ago The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed prot…
CVE-2014-9766 critical 9.8 9.8 FIX slesubuntu ubuntudebian debian pixman 10y ago Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code…
CVE-2015-8833 critical 9.8 9.8 FIX slesdebian debian cypherpunks 10y ago Use-after-free vulnerability in the create_smp_dialog function in gtk-dialog.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 4.0.2 for Pidgin allows remote attackers to execute arbit…
CVE-2015-8710 critical 9.8 9.8 FIX slesdebian debian xmlsoft 10y ago The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possi…
CVE-2015-5313 low 2.5 2.5 FIX debian debian redhat 10y ago Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows l…
CVE-2016-2385 critical 9.8 10.0 EXPFIX debian debian kamailio 10y ago Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a denial of service (memo…
CVE-2016-2513 low 3.1 3.1 FIX debian debian djangoproject 10y ago The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.
CVE-2016-3154 critical 9.8 9.8 FIX debian debian spip 10y ago The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and…
CVE-2016-3153 critical 9.8 9.8 FIX debian debian spip 10y ago SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrer_entites function.
CVE-2016-2324 critical 9.8 9.8 FIX slesdebian debiansuse suse susegit-scm 10y ago Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.
CVE-2016-2315 critical 9.8 9.8 FIX debian debiansuse suse susegit-scm 10y ago revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based b…
CVE-2016-2851 critical 9.8 10.0 EXPFIX slesdebian debiansuse suse cypherpunks 10y ago Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a s…
CVE-2016-2563 critical 9.8 10.0 EXPFIX slesdebian debian 9bissimon_tatham 10y ago Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute…
CVE-2016-0729 critical 9.8 9.8 FIX fedora fedoradebian debian 10y ago Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denia…
CVE-2016-3191 critical 9.8 9.8 FIX slesdebian debian pcre 10y ago The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandles patterns containing an (*ACCEPT) substring in conjunction with nested parent…
CVE-2016-1962 critical 9.8 9.8 FIX debian debiansuse suse mozilla 10y ago Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by…
CVE-2016-1621 critical 9.8 9.8 FIX debian debian 10y ago libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption…
CVE-2016-2842 critical 9.8 9.8 FIX debian debian openssl 10y ago The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows remote attackers to cau…
CVE-2016-0799 critical 9.8 9.8 FIX slesdebian debian opensslpulsesecure 10y ago The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (ov…
CVE-2016-0705 critical 9.8 9.8 FIX debian debianubuntu ubuntu oracleopenssl 10y ago Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory…
CVE-2015-8805 critical 9.8 9.8 FIX debian debianubuntu ubuntususe suse nettle_project 10y ago The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allo…
CVE-2015-8804 critical 9.8 9.8 FIX ubuntu ubuntususe susedebian debian nettle_project 10y ago x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to…
CVE-2015-8803 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu nettle_project 10y ago The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allo…
CVE-2016-1629 critical 9.8 9.8 debian debiansuse suse googlenovell 10y ago Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.
CVE-2016-0746 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu f5applenginx 11y ago Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspeci…
CVE-2016-0701 low 3.7 3.7 FIX slesdebian debian openssl 11y ago The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for…
CVE-2016-2091 low 3.3 3.3 FIX slesdebian debian libdwarf_project 11y ago The dwarf_read_cie_fde_prefix function in dwarf_frame2.c in libdwarf 20151114 allows attackers to cause a denial of service (out-of-bounds read) via a crafted ELF object file.
CVE-2015-8787 critical 9.8 9.8 FIX slesdebian debian linux-kernel 11y ago The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or…
CVE-2016-0801 critical 9.8 10.0 EXPFIX debian debianmacos macos 11y ago The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service …
CVE-2016-1906 critical 9.8 9.8 FIX debian debian kubernetes 11y ago Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.
CVE-2016-1505 critical 10.0 10.0 FIX debian debian radicale 11y ago The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted path, as demonstrated by /c:/file/ignore.
CVE-2015-8747 critical 10.0 10.0 FIX debian debian radicale 11y ago The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name.
CVE-2015-8789 critical 9.6 9.6 FIX debian debian matroska 11y ago Use-after-free vulnerability in the EbmlMaster::Read function in libEBML before 1.3.3 allows context-dependent attackers to have unspecified impact via a "deeply nested element with infinite size" fo…
CVE-2015-7576 low 3.7 3.7 FIX slesdebian debian rubyonrails 11y ago The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22…
CVE-2016-0610 low 3.5 slesdebian debianubuntu ubuntu oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related t…
CVE-2016-0609 low 1.7 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0608 low 3.5 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0606 low 3.5 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0600 low 3.5 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0598 low 3.5 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0592 low 2.1 FIX debian debian oracle 11y ago Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.36 and before 5.0.14 allows local users to affect availability via unknown vectors relat…
CVE-2016-0494 critical 10.0 FIX slesdebian debianubuntu ubuntu oracle 11y ago Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect confidentiality, integrity…
CVE-2016-0483 critical 10.0 FIX slesubuntu ubuntudebian debian oracle 11y ago Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vector…
CVE-2016-1901 critical 9.8 9.8 FIX debian debianfedora fedora cgit_project 11y ago Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer …
CVE-2016-1900 low 3.7 3.7 FIX debian debianfedora fedora cgit_project 11y ago CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP heade…
CVE-2016-1899 low 3.7 3.7 FIX debian debianfedora fedora cgit_project 11y ago CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (X…
CVE-2016-1133 low 3.7 3.7 FIX debian debian dena 11y ago CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTT…
CVE-2015-8396 critical 10.0 10.0 EXPFIX debian debian malaterre 11y ago Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows attackers to execute arbit…
CVE-2015-8659 critical 10.0 10.0 FIX debian debianmacos macos nghttp2 11y ago The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
CVE-2015-7548 low 3.5 3.5 FIX slesdebian debian openstack 11y ago OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read …
CVE-2015-7512 critical 9.0 9.0 FIX rheldebian debian qemuredhat 11y ago Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary …
CVE-2015-8557 critical 9.0 9.0 FIX ubuntu ubuntudebian debian pygments 11y ago The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
CVE-2015-8668 critical 9.8 9.8 FIX slesarch arch rhel libtifforacle 11y ago Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attackers to execute arbitrary code or cause a denial of service …
CVE-2015-7758 low 3.3 3.3 FIX debian debiansuse suse gummi_project 11y ago Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .to…
CVE-2015-7554 critical 9.8 9.8 FIX arch archdebian debian libtiff 11y ago The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field da…
CVE-2015-5254 critical 9.8 9.8 FIX debian debianfedora fedora redhatapache 11y ago Improper Input Validation in Apache ActiveMQ
CVE-2015-6644 low 3.3 3.3 FIX debian debian 11y ago Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.
CVE-2016-1283 critical 9.8 9.8 FIX fedora fedoradebian debian pcrephp 11y ago The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))…
CVE-2015-8569 low 2.3 2.3 FIX slesdebian debian linux-kernel 11y ago The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel through 4.3.3 do not verify an address length, which allows local users to obtain sensitive information …
CVE-2015-7885 low 2.3 2.3 FIX debian debian linux-kernel 11y ago The dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mgmt.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive informa…
CVE-2015-7884 low 2.3 2.3 FIX slesdebian debian linux-kernel 11y ago The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive …
CVE-2015-6619 critical 9.3 FIX debian debian 11y ago The kernel in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, aka internal bug 23520714.
CVE-2015-6764 critical 9.8 9.8 FIX debian debian googlenodejs 11y ago The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which al…
CVE-2015-8394 critical 9.8 9.8 FIX debian debian pcrephp 11y ago PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via …
CVE-2015-8391 critical 9.8 9.8 FIX fedora fedora rheldebian debian pcrephp 11y ago The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecifie…
CVE-2015-8390 critical 9.8 9.8 FIX fedora fedoradebian debian pcrephp 11y ago PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other im…
CVE-2015-8389 critical 9.8 9.8 FIX fedora fedoradebian debian pcrephp 11y ago PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspecified other impact…
CVE-2015-8386 critical 9.8 9.8 FIX fedora fedoradebian debian pcrephp 11y ago PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have …
CVE-2015-8383 critical 9.8 9.8 FIX fedora fedoradebian debian pcrephp 11y ago PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted r…
CVE-2015-5281 low 2.6 FIX debian debian rhel 11y ago The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a …