Search

Found 599 results in 113ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2016-4558 high 7.0 8.0 EXPFIX slesdebian debianubuntu ubuntu 10y ago The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a …
CVE-2016-4486 low 3.3 4.3 EXPFIX slesdebian debianubuntu ubuntu novell 10y ago The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from …
CVE-2016-4485 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu novell 10y ago The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack m…
CVE-2015-8867 high 7.5 7.5 slesubuntu ubuntu php 10y ago The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, w…
CVE-2016-1840 high 7.8 7.8 FIX debian debian rhelubuntu ubuntu xmlsoftmcafee 10y ago Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows …
CVE-2016-1835 high 8.8 8.8 FIX debian debianubuntu ubuntumacos macos 10y ago Use-after-free vulnerability in the xmlSAX2AttributeNs function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2 and OS X before 10.11.5, allows remote attackers to cause a denial of servic…
CVE-2016-1834 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu xmlsoftmcafee 10y ago Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attac…
CVE-2016-3705 high 7.5 7.5 FIX debian debianubuntu ubuntususe suse xmlsofthp 10y ago The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to caus…
CVE-2016-3627 high 7.5 7.5 FIX slesubuntu ubuntudebian debian hpxmlsoftredhat 10y ago The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consum…
CVE-2016-1669 high 8.8 8.8 FIX slesubuntu ubuntudebian debian googlenodejs 10y ago The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows rem…
CVE-2016-3710 high 8.8 8.8 FIX slesubuntu ubuntudebian debian hpqemuoracle 10y ago The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes …
CVE-2016-4556 high 7.5 7.5 FIX slesubuntu ubuntudebian debian squid-cache 10y ago Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.
CVE-2016-4555 high 7.5 7.5 FIX slesubuntu ubuntudebian debian squid-cache 10y ago client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.
CVE-2016-4554 high 8.6 8.6 FIX slesubuntu ubuntudebian debian squid-cache 10y ago mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header sm…
CVE-2016-4553 high 8.6 8.6 FIX slesubuntu ubuntudebian debian squid-cache 10y ago client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks vi…
CVE-2016-4476 high 7.5 7.5 FIX slesarch archubuntu ubuntu w1.fi 10y ago hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of service (daemon outage) …
CVE-2015-8868 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu freedesktop 10y ago Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or poss…
CVE-2016-3716 low 3.3 4.3 EXPFIX debian debian rhelubuntu ubuntu imagemagick 10y ago The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.
CVE-2016-2105 high 7.5 7.5 FIX sles rhelsuse suse oracleopensslnodejs 10y ago Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption)…
CVE-2016-2117 high 7.5 7.5 FIX debian debianubuntu ubuntu linux-kernel 10y ago The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which allows remote attackers to obtain sensitive informa…
CVE-2016-1576 high 7.8 8.8 EXPFIX debian debianubuntu ubuntu linux-kernel 10y ago The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top o…
CVE-2016-1575 high 7.8 8.8 EXPFIX slesdebian debianubuntu ubuntu 10y ago The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid direc…
CVE-2015-8325 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu openbsd 10y ago The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows loc…
CVE-2016-3672 high 7.8 8.8 EXPFIX slesdebian debiansuse suse novell 10y ago The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the int…
CVE-2016-3135 high 7.8 8.8 EXPFIX debian debianubuntu ubuntu linux-kernel 10y ago Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of servi…
CVE-2016-2069 high 7.4 7.4 FIX slesdebian debianubuntu ubuntu 10y ago Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering access to a paging structure by a different CPU.
CVE-2016-4054 high 8.1 8.1 FIX slesubuntu ubuntudebian debian squid-cache 10y ago Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
CVE-2016-4053 low 3.7 3.7 FIX slesubuntu ubuntudebian debian squid-cache 10y ago Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and…
CVE-2016-4052 high 8.1 8.1 FIX slesubuntu ubuntudebian debian squid-cache 10y ago Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (…
CVE-2016-4051 high 8.8 8.8 FIX slesubuntu ubuntudebian debian squid-cache 10y ago Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports wi…
CVE-2016-2113 high 7.4 7.4 FIX slesubuntu ubuntudebian debian samba 10y ago Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and …
CVE-2015-7801 high 8.8 8.8 FIX ubuntu ubuntudebian debian optipng_project 10y ago Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file.
CVE-2015-7511 low 2.0 2.0 FIX slesdebian debianubuntu ubuntu gnupg 10y ago Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring elec…
CVE-2014-9765 high 8.8 8.8 FIX debian debianubuntu ubuntususe suse xdelta 10y ago Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file.
CVE-2016-1655 high 8.8 8.8 debian debianubuntu ubuntususe suse google 10y ago Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or pos…
CVE-2016-1653 high 8.8 8.8 debian debianubuntu ubuntususe suse google 10y ago The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecifie…
CVE-2015-8560 high 7.3 7.3 FIX debian debianubuntu ubuntu linuxfoundation 10y ago Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a …
CVE-2015-3146 high 7.5 7.5 FIX debian debianubuntu ubuntufedora fedora libssh 10y ago The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (…
CVE-2016-3982 high 8.8 8.8 FIX suse suseubuntu ubuntudebian debian optipng_project 10y ago Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly e…
CVE-2016-3981 high 7.8 7.8 FIX ubuntu ubuntudebian debian optipng_project 10y ago Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or p…
CVE-2016-1577 high 7.6 7.6 FIX slesarch archubuntu ubuntu jasper_project 10y ago Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a cr…
CVE-2016-2118 high 7.5 7.5 FIX slesubuntu ubuntudebian debian samba 10y ago The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers …
CVE-2016-3157 high 7.8 7.8 FIX debian debianubuntu ubuntu 10y ago The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which allows local guest OS users to gain privileges, cause…
CVE-2016-2857 high 8.4 8.4 FIX slesubuntu ubuntudebian debian qemuredhat 10y ago The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
CVE-2016-2381 high 7.5 7.5 FIX slessuse suseubuntu ubuntu perloracle 10y ago Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
CVE-2016-2510 high 8.1 8.1 FIX slesdebian debianubuntu ubuntu beanshell 10y ago Improper Input Validation in BeanShell
CVE-2016-3947 high 8.2 8.2 FIX slesubuntu ubuntudebian debian squid-cache 10y ago Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performan…
CVE-2016-3679 high 8.8 8.8 suse suseubuntu ubuntu google 10y ago Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unkn…
CVE-2016-1649 high 8.8 8.8 suse suseubuntu ubuntudebian debian google 10y ago The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attacker…
CVE-2016-1647 high 8.8 8.8 suse suseubuntu ubuntudebian debian google 10y ago Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/renderer_host/render_widget_host_impl.cc in the Navigation implementation in Google Chrome before 49.0.26…
CVE-2016-1762 high 8.1 8.1 FIX debian debianmacos macosubuntu ubuntu applexmlsoftmcafee 10y ago The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
CVE-2016-2856 high 8.4 9.4 EXPFIX debian debianubuntu ubuntu gnu 10y ago pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubuntu 12.04 LTS and before 2.19-0ubuntu6.8 on Ubuntu 14.04 LTS; and the glibc pack…
CVE-2016-1286 high 8.6 8.6 FIX slesdebian debianubuntu ubuntu iscsusejuniper 10y ago named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME r…
CVE-2016-0797 high 7.5 7.5 FIX debian debianubuntu ubuntu opensslnodejs 10y ago Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly …
CVE-2016-0714 high 8.8 8.8 FIX debian debianubuntu ubuntu apache 10y ago The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticat…
CVE-2015-5351 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu apache 10y ago The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, wh…
CVE-2015-5346 high 8.1 8.1 FIX slesdebian debianubuntu ubuntu apache 10y ago Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the sam…
CVE-2016-0795 high 7.8 7.8 FIX debian debianubuntu ubuntu libreoffice 10y ago LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (l…
CVE-2016-0794 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu libreoffice 10y ago The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
CVE-2015-7547 high 8.1 9.1 EXPFIX debian debianubuntu ubuntususe suse hpsophossuse 10y ago Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a den…
CVE-2016-0773 high 7.5 7.5 slesdebian debianubuntu ubuntu postgresql 10y ago PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow a…
CVE-2016-0766 high 8.8 8.8 slesdebian debianubuntu ubuntu postgresql 10y ago PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) fo…
CVE-2016-0742 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu f5appleredhat 10y ago The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
CVE-2016-2330 high 8.8 8.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer size, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified…
CVE-2016-2326 high 8.8 8.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a c…
CVE-2016-0728 high 7.8 8.8 EXPFIX slesdebian debianubuntu ubuntu hp 11y ago The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or…
CVE-2015-8539 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu 11y ago The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to se…
CVE-2016-0755 high 7.3 7.3 FIX debian debianubuntu ubuntu haxx 11y ago The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users vi…
CVE-2016-1572 high 8.4 8.4 FIX slesdebian debianfedora fedora ecryptfs 11y ago mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated…
CVE-2016-0610 low 3.5 slesdebian debianubuntu ubuntu oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related t…
CVE-2016-0609 low 1.7 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0608 low 3.5 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0607 low 2.8 slesubuntu ubuntususe suse oracle 11y ago Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to replication.
CVE-2016-0606 low 3.5 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0600 low 3.5 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0598 low 3.5 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0546 high 7.2 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect co…
CVE-2015-8607 high 7.3 7.3 FIX ubuntu ubuntudebian debian perl 11y ago The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to byp…
CVE-2015-1779 high 8.6 8.6 FIX slesubuntu ubuntu rhel qemuredhat 11y ago The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
CVE-2015-8467 high 7.5 7.5 FIX ubuntu ubuntudebian debian samba 11y ago The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative…
CVE-2015-7540 high 7.5 7.5 FIX ubuntu ubuntudebian debian samba 11y ago The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of se…
CVE-2015-5252 high 7.2 7.2 FIX slesubuntu ubuntudebian debian samba 11y ago vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended f…
CVE-2015-8327 high 7.5 FIX slesdebian debianubuntu ubuntu linuxfoundation 11y ago Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` …
CVE-2015-5277 high 7.2 FIX debian debianubuntu ubuntu rhel gnu 11y ago The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corrup…
CVE-2015-5312 high 7.1 FIX debian debianubuntu ubuntu rhel xmlsofthp 11y ago Nokogiri subject to DoS via libxml2 vulnerability
CVE-2015-1344 high 7.2 FIX ubuntu ubuntudebian debian canonical 11y ago The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to the tasks file.
CVE-2015-3194 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu opensslnodejs 11y ago crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.…
CVE-2015-3193 high 7.5 7.5 FIX slesubuntu ubuntudebian debian opensslnodejs 11y ago The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and pro…
CVE-2015-0860 high 7.5 FIX slesdebian debianubuntu ubuntu debian 11y ago Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrar…
CVE-2015-8035 low 2.6 FIX slesdebian debianubuntu ubuntu xmlsoft 11y ago The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML da…
CVE-2015-8126 high 7.5 FIX slesdebian debianubuntu ubuntu libpngredhatoracle 11y ago Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x …
CVE-2015-8025 low 2.1 FIX slesubuntu ubuntudebian debian xscreensaver_project 11y ago driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.
CVE-2015-2696 high 7.1 FIX slesdebian debianubuntu ubuntu mit 11y ago lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and pro…
CVE-2015-6855 high 7.5 7.5 FIX debian debianubuntu ubuntususe suse qemu 11y ago hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain …
CVE-2015-4913 low 3.5 ubuntu ubuntudebian debiansuse suse oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vu…
CVE-2015-4895 low 3.5 ubuntu ubuntudebian debianfedora fedora oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
CVE-2015-4864 low 3.5 ubuntu ubuntu rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Pri…
CVE-2015-4861 low 3.5 ubuntu ubuntudebian debiansuse suse oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
CVE-2015-4836 low 2.8 ubuntu ubuntudebian debiansuse suse oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : SP.
CVE-2015-4819 high 7.2 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to C…