Search

Found 1,547 results in 365ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2015-4487 high 7.5 ubuntu ubuntususe suse mozilla 11y ago The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corrup…
CVE-2015-4486 critical 10.0 FIX debian debianubuntu ubuntususe suse mozilla 11y ago The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds…
CVE-2015-4485 critical 10.0 FIX debian debianubuntu ubuntususe suse mozilla 11y ago Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via malfo…
CVE-2015-4484 medium 5.0 ubuntu ubuntususe suse mozilla 11y ago The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of servi…
CVE-2015-4480 critical 9.3 ubuntu ubuntususe suse mozilla 11y ago Integer overflow in the stagefright::SampleTable::isValid function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code …
CVE-2015-4479 critical 10.0 ubuntu ubuntususe suse mozilla 11y ago Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to execute arbitrary code via a crafted saio chunk in MPEG-4 video …
CVE-2015-4478 medium 5.0 ubuntu ubuntususe suse mozilla 11y ago Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which allows remote attackers to bypass the Same Origin P…
CVE-2015-4477 critical 10.0 ubuntu ubuntususe suse mozilla 11y ago Use-after-free vulnerability in the MediaStream playback feature in Mozilla Firefox before 40.0 allows remote attackers to execute arbitrary code via unspecified use of the Web Audio API.
CVE-2015-4475 high 7.5 ubuntu ubuntususe suse mozilla 11y ago The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute …
CVE-2015-4474 critical 10.0 ubuntu ubuntususe suse mozilla 11y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly exe…
CVE-2015-4473 critical 10.0 slesubuntu ubuntudebian debian mozilla 11y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to cause a denial of service (memory corruption and a…
CVE-2013-7443 medium 5.0 FIX ubuntu ubuntudebian debian sqlite 11y ago Buffer overflow in the skip-scan optimization in SQLite 3.8.2 allows remote attackers to cause a denial of service (crash) via crafted SQL statements.
CVE-2015-5523 medium 4.3 ubuntu ubuntudebian debianmacos macos htacg 11y ago The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which …
CVE-2015-5522 medium 6.8 ubuntu ubuntudebian debianmacos macos htacg 11y ago Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an hre…
CVE-2015-3636 medium 4.9 FIX debian debian rhelubuntu ubuntu 11y ago The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges …
CVE-2015-4167 medium 4.7 FIX slesdebian debianubuntu ubuntu 11y ago The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values, which allows local users to cause a denial of service (incorrect data represen…
CVE-2015-1872 medium 6.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago The ff_mjpeg_decode_sof function in libavcodec/mjpegdec.c in FFmpeg before 2.5.4 does not validate the number of components in a JPEG-LS Start Of Frame segment, which allows remote attackers to cause…
CVE-2015-1283 medium 6.8 FIX slesdebian debianubuntu ubuntu googlelibexpat_projectpython 11y ago Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (…
CVE-2015-3185 medium 4.3 FIX debian debianubuntu ubuntumacos macos apacheapple 11y ago The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather …
CVE-2015-4772 medium 4.0 ubuntu ubuntu oracle 11y ago Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition.
CVE-2015-4752 medium 4.0 rhelubuntu ubuntudebian debian oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to Server : I_S.
CVE-2015-2648 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to DML.
CVE-2015-2643 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
CVE-2015-2620 medium 4.3 ubuntu ubuntudebian debian juniperoraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security…
CVE-2015-2617 medium 6.5 ubuntu ubuntu oracle 11y ago Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Partition.
CVE-2015-2611 medium 4.0 ubuntu ubuntu oracle 11y ago Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to DML.
CVE-2015-2582 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to GIS.
CVE-2015-5144 medium 4.3 FIX ubuntu ubuntudebian debian djangoproject 11y ago Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP …
CVE-2015-5143 high 7.8 FIX ubuntu ubuntudebian debian djangoproject 11y ago The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via mult…
CVE-2015-3279 high 7.5 FIX debian debianubuntu ubuntu linuxfoundation 11y ago Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line si…
CVE-2015-3258 high 7.5 FIX debian debianubuntu ubuntu linuxfoundation 11y ago Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execut…
CVE-2015-3281 medium 5.0 FIX debian debianubuntu ubuntu rhel haproxy 11y ago The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitiv…
CVE-2015-2740 critical 10.0 ubuntu ubuntudebian debiansuse suse mozillanovell 11y ago Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remot…
CVE-2015-2739 critical 10.0 ubuntu ubuntudebian debiansuse suse mozillanovell 11y ago The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has …
CVE-2015-2738 critical 10.0 ubuntu ubuntudebian debiansuse suse mozilla 11y ago The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1…
CVE-2015-2737 critical 10.0 ubuntu ubuntudebian debiansuse suse mozilla 11y ago The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from …
CVE-2015-2736 critical 9.3 ubuntu ubuntudebian debiansuse suse mozillanovell 11y ago The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which all…
CVE-2015-2735 critical 9.3 ubuntu ubuntudebian debiansuse suse mozillanovell 11y ago nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to …
CVE-2015-2734 critical 10.0 ubuntu ubuntudebian debiansuse suse mozilla 11y ago The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 r…
CVE-2015-2724 critical 10.0 ubuntu ubuntudebian debiansuse suse mozillanovell 11y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cau…
CVE-2015-2721 medium 4.3 FIX debian debianubuntu ubuntususe suse novellmozilla 11y ago Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not p…
CVE-2015-1330 medium 6.8 FIX ubuntu ubuntudebian debian debian 11y ago unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which all…
CVE-2015-1851 medium 6.8 FIX debian debianubuntu ubuntu openstack 11y ago OpenStack Cinder file disclosure in image convert
CVE-2015-3395 medium 6.8 FIX debian debianubuntu ubuntu ffmpeglibav 11y ago The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 all…
CVE-2015-3209 high 7.5 FIX ubuntu ubuntudebian debian rhel qemujuniperredhat 11y ago Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_…
CVE-2015-3905 high 7.5 FIX ubuntu ubuntudebian debian t1utils_project 11y ago Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font f…
CVE-2015-4004 high 8.5 FIX debian debian linux-kernelubuntu ubuntu 11y ago The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or caus…
CVE-2015-4002 critical 9.0 FIX debian debian linux-kernelsuse suse 11y ago drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 does not ensure that certain length values are sufficiently large, which allows remote attackers to cause a d…
CVE-2015-4106 medium 4.6 FIX suse susedebian debianfedora fedora qemucitrix 11y ago QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host c…
CVE-2015-4047 high 7.8 slesdebian debianfedora fedora ipsec-toolsf5 11y ago racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
CVE-2015-0847 high 7.8 FIX debian debianubuntu ubuntu wouter_verhelst 11y ago nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of service (deadlock) via unspecified vectors.
CVE-2015-3165 medium 4.3 debian debianubuntu ubuntu postgresql 11y ago Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash…
CVE-2015-3331 critical 9.3 FIX debian debian linux-kernelubuntu ubuntu 11y ago The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows co…
CVE-2015-3409 high 7.2 FIX debian debianubuntu ubuntu module-signature_project 11y ago Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan h…
CVE-2015-3408 critical 10.0 FIX debian debianubuntu ubuntu module-signature_project 11y ago Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled when generating checksums from a signed manifest.
CVE-2015-3407 medium 5.0 FIX debian debianubuntu ubuntu module-signature_project 11y ago Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
CVE-2015-3451 medium 5.0 FIX debian debianubuntu ubuntususe suse xml-libxml_project 11y ago The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to t…
CVE-2015-2668 medium 5.0 FIX debian debianubuntu ubuntu clamav 11y ago ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file.
CVE-2015-2222 medium 5.0 FIX debian debianubuntu ubuntu clamav 11y ago ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file.
CVE-2015-2221 medium 5.0 FIX debian debianubuntu ubuntu clamav 11y ago ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.
CVE-2015-2170 medium 5.0 FIX debian debianubuntu ubuntu clamav 11y ago The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
CVE-2015-3153 medium 5.0 FIX debian debianubuntu ubuntumacos macos oraclehaxx 11y ago The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information…
CVE-2015-1250 high 7.5 ubuntu ubuntudebian debian google 11y ago Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1243 high 7.5 ubuntu ubuntudebian debian google 11y ago Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows re…
CVE-2015-1322 medium 4.6 FIX debian debianubuntu ubuntu ubuntu 11y ago Directory traversal vulnerability in the Ubuntu network-manager package for Ubuntu (vivid) before 0.9.10.0-4ubuntu15.1, Ubuntu 14.10 before 0.9.8.8-0ubuntu28.1, and Ubuntu 14.04 LTS before 0.9.8.8-0u…
CVE-2015-1321 medium 6.8 ubuntu ubuntu oxide_project 11y ago Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webp…
CVE-2015-1863 medium 5.8 FIX slesubuntu ubuntudebian debian w1.fi 11y ago Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information…
CVE-2015-1774 medium 6.8 FIX debian debianubuntu ubuntu rhel apachelibreoffice 11y ago The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code vi…
CVE-2015-3416 high 7.5 FIX slesubuntu ubuntudebian debian sqlitephp 11y ago The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to caus…
CVE-2015-3415 high 7.5 FIX slesubuntu ubuntudebian debian sqlitephp 11y ago The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free ope…
CVE-2015-3414 high 7.5 FIX slesubuntu ubuntudebian debian sqlitephp 11y ago SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and appli…
CVE-2015-3310 medium 4.3 FIX ubuntu ubuntudebian debian point-to-point_protocol_project 11y ago Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial…
CVE-2015-3148 medium 5.0 FIX debian debianubuntu ubuntususe suse haxxhp 11y ago cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
CVE-2015-3145 high 7.5 FIX debian debianubuntu ubuntususe suse haxxhp 11y ago The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and c…
CVE-2015-3144 critical 9.0 FIX debian debianubuntu ubuntu oraclehaxx 11y ago The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and c…
CVE-2015-3143 medium 5.0 FIX debian debianubuntu ubuntumacos macos haxxhp 11y ago cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0…
CVE-2015-3333 high 7.5 ubuntu ubuntudebian debian google 11y ago Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknow…
CVE-2015-1249 high 7.5 ubuntu ubuntudebian debian google 11y ago Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1244 medium 5.0 ubuntu ubuntudebian debian google 11y ago The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which…
CVE-2015-1242 high 7.5 ubuntu ubuntudebian debian google 11y ago The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of ser…
CVE-2015-1241 medium 4.3 ubuntu ubuntudebian debian rhel google 11y ago Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintend…
CVE-2015-1240 medium 5.0 ubuntu ubuntudebian debian google 11y ago gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL p…
CVE-2015-1238 high 7.5 ubuntu ubuntudebian debian google 11y ago Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
CVE-2015-1237 high 7.5 ubuntu ubuntudebian debian google 11y ago Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial…
CVE-2015-1236 medium 4.3 ubuntu ubuntudebian debian google 11y ago The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allow…
CVE-2015-1235 medium 5.0 ubuntu ubuntudebian debian google 11y ago The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origi…
CVE-2015-1856 medium 5.5 FIX ubuntu ubuntudebian debian openstack 11y ago OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-vers…
CVE-2015-1852 medium 4.3 FIX ubuntu ubuntudebian debian openstack 11y ago The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configurat…
CVE-2015-2573 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
CVE-2015-2571 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
CVE-2015-2568 medium 5.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileg…
CVE-2015-0501 medium 5.7 ubuntu ubuntudebian debian rhel juniperoraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.
CVE-2015-0441 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Security …
CVE-2015-0433 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
CVE-2013-7439 high 7.5 FIX debian debianubuntu ubuntu x.org 11y ago Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted r…
CVE-2015-1819 medium 5.0 FIX debian debian rhelubuntu ubuntu xmlsoft 11y ago The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
CVE-2015-2775 high 7.6 slesubuntu ubuntudebian debian gnu 11y ago Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
CVE-2015-0840 medium 4.3 FIX debian debianubuntu ubuntu debian 11y ago The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).
CVE-2015-2806 critical 10.0 FIX debian debianubuntu ubuntufedora fedora gnu 11y ago Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.
CVE-2015-1317 high 7.5 ubuntu ubuntu oxide_project 11y ago Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents w…