7.8

CVE-2015-1414

Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netgate ≫ Pfsense Version 2.2.1
Debian ≫ Debian Linux Version 7.0
Freebsd ≫ Freebsd Version 8.4
Freebsd ≫ Freebsd Version 9.0
Freebsd ≫ Freebsd Version 9.1
Freebsd ≫ Freebsd Version 9.2
Freebsd ≫ Freebsd Version 9.3
Freebsd ≫ Freebsd Version 10.0
Freebsd ≫ Freebsd Version 10.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.15% 0.896
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.debian.org/security/2015/dsa-3175
Third Party Advisory
http://www.securityfocus.com/bid/72777
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1031798
Third Party Advisory
VDB Entry
https://kc.mcafee.com/corporate/index?page=content&id=SB10107
https://www.freebsd.org/security/advisories/FreeBSD-SA-15:04.igmp.asc
Vendor Advisory
https://www.pfsense.org/security/advisories/pfSense-SA-15_02.igmp.asc
Third Party Advisory