5

CVE-2015-3281

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.

Data is provided by the National Vulnerability Database (NVD)
DebianDebian Linux Version8.0
HaproxyHaproxy Version1.5 Updatedev
HaproxyHaproxy Version1.5 Updatedev0
HaproxyHaproxy Version1.5 Updatedev1
HaproxyHaproxy Version1.5 Updatedev10
HaproxyHaproxy Version1.5 Updatedev11
HaproxyHaproxy Version1.5 Updatedev12
HaproxyHaproxy Version1.5 Updatedev13
HaproxyHaproxy Version1.5 Updatedev14
HaproxyHaproxy Version1.5 Updatedev15
HaproxyHaproxy Version1.5 Updatedev16
HaproxyHaproxy Version1.5 Updatedev17
HaproxyHaproxy Version1.5 Updatedev18
HaproxyHaproxy Version1.5 Updatedev19
HaproxyHaproxy Version1.5 Updatedev2
HaproxyHaproxy Version1.5 Updatedev3
HaproxyHaproxy Version1.5 Updatedev4
HaproxyHaproxy Version1.5 Updatedev5
HaproxyHaproxy Version1.5 Updatedev6
HaproxyHaproxy Version1.5 Updatedev7
HaproxyHaproxy Version1.5 Updatedev8
HaproxyHaproxy Version1.5 Updatedev9
HaproxyHaproxy Version1.5.0
HaproxyHaproxy Version1.5.1
HaproxyHaproxy Version1.5.2
HaproxyHaproxy Version1.5.3
HaproxyHaproxy Version1.5.4
HaproxyHaproxy Version1.5.5
HaproxyHaproxy Version1.5.6
HaproxyHaproxy Version1.5.7
HaproxyHaproxy Version1.5.8
HaproxyHaproxy Version1.5.9
HaproxyHaproxy Version1.5.10
HaproxyHaproxy Version1.5.11
HaproxyHaproxy Version1.5.12
HaproxyHaproxy Version1.5.13
HaproxyHaproxy Version1.6 Updatedev0
CanonicalUbuntu Linux Version14.10
CanonicalUbuntu Linux Version15.04
OpensuseOpenstack Cloud Version5
OpensuseOpensuse Version13.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.236
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.