CVE-2016-5244
- EPSS 0.77%
- Published 27.06.2016 10:59:11
- Last modified 12.04.2025 10:46:40
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.
CVE-2016-3951
- EPSS 0.02%
- Published 02.05.2016 10:59:41
- Last modified 12.04.2025 10:46:40
Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invali...
CVE-2015-8845
- EPSS 0.07%
- Published 27.04.2016 17:59:05
- Last modified 12.04.2025 10:46:40
The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a denial of ...
CVE-2015-3340
- EPSS 0.63%
- Published 28.04.2015 14:59:02
- Last modified 12.04.2025 10:46:40
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.
- EPSS 0.93%
- Published 16.04.2015 16:59:49
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors.
- EPSS 1.01%
- Published 16.04.2015 16:59:04
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-4756.
CVE-2013-1864
- EPSS 2.73%
- Published 23.05.2014 14:55:09
- Last modified 12.04.2025 10:46:40
The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXM...
CVE-2014-1496
- EPSS 0.06%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
- EPSS 1.47%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and app...
CVE-2014-1497
- EPSS 0.5%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause...