Search

Found 820 results in 210ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2016-4581 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu 10y ago fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL …
CVE-2016-4578 medium 5.5 6.5 EXPFIX sles linux-kerneldebian debian 10y ago sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of…
CVE-2016-4569 medium 5.5 5.5 FIX slessuse susedebian debian novell 10y ago The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from ke…
CVE-2016-4482 medium 6.2 6.2 FIX slesubuntu ubuntususe suse novell 10y ago The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from k…
CVE-2016-4441 medium 6.0 6.0 FIX slesubuntu ubuntudebian debian qemu 10y ago The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local guest OS administrators to cause a denial of servi…
CVE-2016-4439 medium 6.7 6.7 FIX slesubuntu ubuntudebian debian qemu 10y ago The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause …
CVE-2016-1839 medium 5.5 6.5 EXPFIX slesdebian debian rhel mcafeexmlsoft 10y ago The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial o…
CVE-2016-1838 medium 5.5 6.5 EXPFIX debian debian rhelubuntu ubuntu mcafeexmlsoft 10y ago The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to…
CVE-2016-1837 medium 5.5 5.5 FIX debian debianubuntu ubuntumacos macos mcafeexmlsoft 10y ago Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS …
CVE-2016-1836 medium 5.5 5.5 FIX debian debianubuntu ubuntumacos macos xmlsoftmcafee 10y ago Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows…
CVE-2016-1833 medium 5.5 5.5 FIX debian debianubuntu ubuntumacos macos xmlsoftmcafee 10y ago The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of…
CVE-2016-3712 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian qemucitrix 10y ago Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.
CVE-2016-4008 medium 5.9 5.9 FIX slesdebian debiansuse suse gnu 10y ago The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infini…
CVE-2016-3717 medium 5.5 6.5 EXPFIX debian debian rhelubuntu ubuntu imagemagick 10y ago The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
CVE-2016-2107 medium 5.9 6.9 EXPFIX sles rhelsuse suse opensslhpnodejs 10y ago The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleart…
CVE-2016-3951 medium 4.6 4.6 FIX slesdebian debiansuse suse novellsuse 10y ago Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified ot…
CVE-2016-3689 medium 4.6 4.6 FIX slesdebian debiansuse suse novell 10y ago The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device…
CVE-2016-3140 medium 4.6 5.6 EXPFIX slesdebian debiansuse suse novell 10y ago The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and s…
CVE-2016-3138 medium 4.6 4.6 FIX slesdebian debiansuse suse novell 10y ago The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) v…
CVE-2016-3137 medium 4.6 4.6 FIX debian debiansuse suseubuntu ubuntu novell 10y ago drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device withou…
CVE-2016-3136 medium 4.6 5.6 EXPFIX debian debiansuse suseubuntu ubuntu novell 10y ago The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and s…
CVE-2016-2188 medium 4.6 5.6 EXPFIX debian debiansuse suseubuntu ubuntu novell 10y ago The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system c…
CVE-2016-2187 medium 4.6 4.6 FIX slesdebian debiansuse suse novell 10y ago The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash)…
CVE-2016-2186 medium 4.6 4.6 FIX debian debiansuse suseubuntu ubuntu novell 10y ago The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system…
CVE-2016-2185 medium 4.6 4.6 FIX debian debiansuse suseubuntu ubuntu novell 10y ago The ati_remote2_probe function in drivers/input/misc/ati_remote2.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and sy…
CVE-2015-8839 medium 5.1 5.1 FIX slesdebian debianubuntu ubuntu 10y ago Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk corruption) by writing to a page that is associated …
CVE-2016-3156 medium 5.5 5.5 FIX slesdebian debiansuse suse novell 10y ago The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging fo…
CVE-2016-2383 medium 5.5 5.5 FIX slesdebian debiansuse suse 10y ago The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information fr…
CVE-2016-2184 medium 4.6 5.6 EXPFIX debian debiansuse suseubuntu ubuntu novell 10y ago The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL poin…
CVE-2016-2115 medium 5.9 5.9 FIX slesubuntu ubuntudebian debian samba 10y ago Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB c…
CVE-2016-2114 medium 5.9 5.9 FIX slesubuntu ubuntudebian debian samba 10y ago The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle att…
CVE-2016-2112 medium 5.9 5.9 FIX slesubuntu ubuntudebian debian samba 10y ago The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-midd…
CVE-2016-2111 medium 6.3 6.3 FIX slesubuntu ubuntudebian debian samba 10y ago The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows remote attackers to spoof the computer name of a se…
CVE-2016-2110 medium 5.9 5.9 FIX slesubuntu ubuntudebian debian samba 10y ago The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by mo…
CVE-2015-5370 medium 5.9 5.9 FIX slesubuntu ubuntudebian debian samba 10y ago Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a…
CVE-2013-7449 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu xchathexchat_project 10y ago The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows m…
CVE-2016-0668 medium 4.1 4.1 slessuse susedebian debian oraclemariadb 10y ago Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 and 10.1.x before 10.1.12 allows local users to affect availability via vectors r…
CVE-2016-0665 medium 5.5 5.5 sles rhelubuntu ubuntu oracle 10y ago Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Security: Encryption.
CVE-2016-0661 medium 4.7 4.7 sles rhelubuntu ubuntu oracle 10y ago Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Options.
CVE-2016-0642 medium 4.7 4.7 sles rhelsuse suse oraclesusemariadb 10y ago Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier allows local users to affect integrity and availability via vectors related to Federated.
CVE-2015-7802 medium 5.5 5.5 FIX ubuntu ubuntudebian debian optipng_project 10y ago gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.
CVE-2016-3941 medium 5.5 5.5 FIX ubuntu ubuntudebian debian videolan 10y ago Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, rela…
CVE-2016-1654 medium 6.5 6.5 debian debianubuntu ubuntususe suse google 10y ago The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unk…
CVE-2016-3961 medium 5.5 5.5 FIX debian debianubuntu ubuntu 10y ago Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to…
CVE-2015-5247 medium 6.5 6.5 FIX debian debianubuntu ubuntu redhat 10y ago The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unl…
CVE-2011-4600 medium 5.9 5.9 FIX debian debianubuntu ubuntu redhat 10y ago The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow rem…
CVE-2016-0739 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu libssh 10y ago libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-i…
CVE-2016-2191 medium 6.5 6.5 FIX suse suseubuntu ubuntudebian debian optipng 10y ago The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a craf…
CVE-2015-8552 medium 4.4 4.4 FIX debian debianubuntu ubuntu 10y ago The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messag…
CVE-2016-2116 medium 5.7 5.7 FIX slesarch archubuntu ubuntu jasper_project 10y ago Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG…
CVE-2016-2858 medium 6.5 6.5 FIX slesubuntu ubuntudebian debian qemu 10y ago QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbit…
CVE-2015-7560 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu samba 10y ago The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by usi…
CVE-2016-1285 medium 6.8 6.8 FIX slesdebian debiansuse suse iscsusejuniper 10y ago named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service …
CVE-2016-2774 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu isc 10y ago ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertio…
CVE-2016-0702 medium 5.1 5.1 FIX debian debianubuntu ubuntu opensslnodejs 10y ago The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiati…
CVE-2016-0763 medium 6.3 6.3 FIX debian debianubuntu ubuntu apache 10y ago The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLink…
CVE-2016-0706 medium 4.3 4.3 FIX slesdebian debianubuntu ubuntu apache 10y ago Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/Restrict…
CVE-2015-5345 medium 5.3 5.3 FIX slesdebian debianubuntu ubuntu apache 10y ago The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which a…
CVE-2015-5174 medium 4.3 4.3 slesdebian debianubuntu ubuntu apache 10y ago Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
CVE-2013-7447 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu 10y ago Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8, as used in eom, gnome-photos, eog, gambas3, thunar, pinpoint, and possibly other applications, all…
CVE-2016-0747 medium 5.3 5.3 FIX slesdebian debianubuntu ubuntu f5applenginx 10y ago The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) v…
CVE-2016-2073 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu xmlsoft 11y ago The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document.
CVE-2015-8767 medium 6.2 6.2 FIX slesdebian debianubuntu ubuntu 11y ago net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a c…
CVE-2015-7513 medium 6.5 6.5 FIX slesdebian debianfedora fedora 11y ago arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and ho…
CVE-2016-1947 medium 4.7 4.7 ubuntu ubuntususe suse mozilla 11y ago Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of re…
CVE-2016-2047 medium 5.9 5.9 slesdebian debianubuntu ubuntu mariadboracle 11y ago The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 …
CVE-2016-0616 medium 4.0 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via u…
CVE-2016-0611 medium 4.0 slesubuntu ubuntususe suse oracle 11y ago Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
CVE-2016-0597 medium 4.0 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0596 medium 4.0 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to af…
CVE-2016-0595 medium 4.0 slesubuntu ubuntususe suse oracle 11y ago Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML.
CVE-2016-0505 medium 6.8 slesdebian debianubuntu ubuntu oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0504 medium 6.8 slesubuntu ubuntususe suse oracle 11y ago Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-050…
CVE-2016-0503 medium 4.0 slesubuntu ubuntususe suse oracle 11y ago Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-050…
CVE-2016-0466 medium 5.0 FIX slesubuntu ubuntudebian debian oracle 11y ago Unspecified vulnerability in the Java SE, Java SE Embedded, and JRockit components in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affec…
CVE-2016-0448 medium 4.0 FIX slesubuntu ubuntudebian debian oracle 11y ago Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66, and Java SE Embedded 8u65 allows remote authenticated users to affect confidentiality…
CVE-2016-0402 medium 5.0 FIX slesubuntu ubuntudebian debian oracle 11y ago Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect integrity via unknown vect…
CVE-2015-7499 medium 5.0 FIX debian debianubuntu ubuntu rhel hpxmlsoft 11y ago Heap-based buffer overflow in nokogiri
CVE-2016-1898 medium 5.5 5.5 FIX debian debianubuntu ubuntususe suse ffmpeg 11y ago FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP reques…
CVE-2016-1897 medium 5.5 5.5 FIX debian debianubuntu ubuntususe suse ffmpeg 11y ago FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request…
CVE-2015-8605 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu sophosisc 11y ago ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
CVE-2015-7575 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu mozilla 11y ago Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in T…
CVE-2015-5299 medium 5.3 5.3 FIX slesubuntu ubuntudebian debian samba 11y ago The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST acc…
CVE-2015-5296 medium 5.4 5.4 FIX slesubuntu ubuntudebian debian samba 11y ago Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unen…
CVE-2015-8317 medium 5.0 FIX slesdebian debianubuntu ubuntu xmlsofthp 11y ago The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declar…
CVE-2015-8242 medium 5.8 FIX slesdebian debianubuntu ubuntu xmlsofthp 11y ago The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read a…
CVE-2015-8241 medium 6.4 FIX slesdebian debianubuntu ubuntu hpxmlsoft 11y ago The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) …
CVE-2015-7500 medium 5.0 FIX debian debianubuntu ubuntu rhel hpxmlsoft 11y ago The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect en…
CVE-2015-7498 medium 5.0 FIX debian debianubuntu ubuntu rhel hpxmlsoft 11y ago Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extra…
CVE-2015-7497 medium 5.0 FIX debian debianubuntu ubuntu rhel xmlsofthp 11y ago Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.
CVE-2015-1342 medium 4.6 FIX debian debianubuntu ubuntu canonical 11y ago LXCFS before 0.12 does not properly enforce directory escapes, which might allow local users to gain privileges by (1) querying or (2) updating a cgroup.
CVE-2015-3196 medium 4.3 FIX slesdebian debianfedora fedora hpopenssloracle 11y ago ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which a…
CVE-2015-3195 medium 5.3 5.3 FIX macos macossuse susedebian debian oracleopenssl 11y ago The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_…
CVE-2015-8365 medium 6.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the data size is consistent with the number of channels…
CVE-2015-8364 medium 6.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows remote attackers to cause a denial of service (out-o…
CVE-2015-7981 medium 5.0 slesdebian debian rhel libpng 11y ago The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via cra…
CVE-2015-7869 medium 6.6 FIX ubuntu ubuntu linux-kerneldebian debian nvidia 11y ago Multiple integer overflows in the kernel mode driver for the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows and R304 before 304.131, R340 before …
CVE-2014-9756 medium 5.0 FIX slesdebian debiansuse suse libsndfile_project 11y ago The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable.
CVE-2015-8023 medium 5.0 FIX slesubuntu ubuntudebian debian strongswan 11y ago The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers t…
CVE-2015-7942 medium 6.8 FIX debian debianubuntu ubuntumacos macos hpxmlsoft 11y ago The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a d…