CVE-2013-6501
- EPSS 0.05%
- Veröffentlicht 30.03.2015 10:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp wit...
- EPSS 2.45%
- Veröffentlicht 02.03.2015 11:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass in...
- EPSS 0.42%
- Veröffentlicht 21.01.2015 19:59:17
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.
- EPSS 3.14%
- Veröffentlicht 21.01.2015 18:59:35
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
CVE-2015-0382
- EPSS 15.18%
- Veröffentlicht 21.01.2015 18:59:27
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381.
CVE-2015-0381
- EPSS 5.03%
- Veröffentlicht 21.01.2015 18:59:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382.
CVE-2015-0374
- EPSS 0.24%
- Veröffentlicht 21.01.2015 18:59:21
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Foreign Key.
CVE-2014-6568
- EPSS 2.94%
- Veröffentlicht 21.01.2015 15:28:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.
CVE-2014-9585
- EPSS 0.05%
- Veröffentlicht 09.01.2015 21:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the ...
CVE-2014-9584
- EPSS 0.13%
- Veröffentlicht 09.01.2015 21:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel...