CVE-2015-8126
- EPSS 4.95%
- Published 13.11.2015 03:59:05
- Last modified 12.04.2025 10:46:40
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a den...
- EPSS 1.12%
- Published 09.11.2015 16:59:09
- Last modified 12.04.2025 10:46:40
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "...
- EPSS 6.39%
- Published 09.11.2015 03:59:03
- Last modified 12.04.2025 10:46:40
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field...
CVE-2015-2696
- EPSS 8.28%
- Published 09.11.2015 03:59:02
- Last modified 12.04.2025 10:46:40
lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mis...
- EPSS 4.77%
- Published 09.11.2015 03:59:00
- Last modified 12.04.2025 10:46:40
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that...
CVE-2015-6031
- EPSS 2.8%
- Published 02.11.2015 19:59:14
- Last modified 12.04.2025 10:46:40
Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversiz...
CVE-2015-5291
- EPSS 1.7%
- Published 02.11.2015 19:59:05
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a lon...
CVE-2015-4913
- EPSS 0.39%
- Published 22.10.2015 00:00:16
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.
- EPSS 9.38%
- Published 22.10.2015 00:00:03
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
- EPSS 19.34%
- Published 21.10.2015 23:59:34
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.