- EPSS 1.08%
- Veröffentlicht 17.11.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215.
CVE-2015-8126
- EPSS 4.95%
- Veröffentlicht 13.11.2015 03:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a den...
- EPSS 6.39%
- Veröffentlicht 09.11.2015 03:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field...
CVE-2015-2696
- EPSS 8.28%
- Veröffentlicht 09.11.2015 03:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mis...
- EPSS 4.77%
- Veröffentlicht 09.11.2015 03:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that...
CVE-2015-6855
- EPSS 5.77%
- Veröffentlicht 06.11.2015 21:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_...
- EPSS 0.3%
- Veröffentlicht 21.10.2015 21:59:44
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.
CVE-2015-7645
- EPSS 84.84%
- Veröffentlicht 15.10.2015 10:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
CVE-2015-1781
- EPSS 7.79%
- Veröffentlicht 28.09.2015 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS respo...
CVE-2015-5154
- EPSS 0.2%
- Veröffentlicht 12.08.2015 14:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.