CVE-2015-3329
- EPSS 28.15%
- Veröffentlicht 09.06.2015 18:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) ph...
CVE-2015-3307
- EPSS 18.41%
- Veröffentlicht 09.06.2015 18:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a craf...
CVE-2015-2783
- EPSS 9.68%
- Veröffentlicht 09.06.2015 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read and application crash) via a crafted length v...
CVE-2015-1863
- EPSS 5.38%
- Veröffentlicht 28.04.2015 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management frame when creating or updating P2...
CVE-2015-1241
- EPSS 2.19%
- Veröffentlicht 19.04.2015 10:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts ...
- EPSS 1.52%
- Veröffentlicht 08.04.2015 18:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
- EPSS 17.76%
- Veröffentlicht 08.04.2015 18:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evalu...
CVE-2015-2787
- EPSS 36.43%
- Veröffentlicht 30.03.2015 10:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call th...
- EPSS 7.24%
- Veröffentlicht 30.03.2015 10:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extens...
CVE-2015-2301
- EPSS 17.29%
- Veröffentlicht 30.03.2015 10:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an a...