10
CVE-2015-0235
- EPSS 85.45%
- Published 28.01.2015 19:59:00
- Last modified 12.04.2025 10:46:40
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
Data is provided by the National Vulnerability Database (NVD)
Oracle ≫ Communications Application Session Controller Version < 3.7.1
Oracle ≫ Communications Eagle Application Processor Version16.0
Oracle ≫ Communications Eagle Lnp Application Processor Version10.0
Oracle ≫ Communications Lsms Version13.1
Oracle ≫ Communications Policy Management Version9.7.3
Oracle ≫ Communications Policy Management Version9.9.1
Oracle ≫ Communications Policy Management Version10.4.1
Oracle ≫ Communications Policy Management Version11.5
Oracle ≫ Communications Policy Management Version12.1.1
Oracle ≫ Communications Session Border Controller Version < 7.2.0
Oracle ≫ Communications Session Border Controller Version7.2.0 Update-
Oracle ≫ Communications Session Border Controller Version8.0.0
Oracle ≫ Communications User Data Repository Version >= 10.0.0 <= 10.0.1
Oracle ≫ Communications Webrtc Session Controller Version7.0
Oracle ≫ Communications Webrtc Session Controller Version7.1
Oracle ≫ Communications Webrtc Session Controller Version7.2
Oracle ≫ Exalogic Infrastructure Version1.0
Oracle ≫ Exalogic Infrastructure Version2.0
Oracle ≫ Vm Virtualbox Version < 5.1.24
Debian ≫ Debian Linux Version7.0
Debian ≫ Debian Linux Version8.0
Redhat ≫ Virtualization Version6.0
Ibm ≫ Pureapplication System Version1.0.0.0
Ibm ≫ Pureapplication System Version1.1.0.0
Ibm ≫ Pureapplication System Version2.0.0.0
Ibm ≫ Security Access Manager For Enterprise Single Sign-on Version8.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 85.45% | 0.993 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.