CVE-2015-5165
- EPSS 10.86%
- Veröffentlicht 12.08.2015 14:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
- EPSS 12.98%
- Veröffentlicht 20.07.2015 23:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending...
- EPSS 75.52%
- Veröffentlicht 09.06.2015 18:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form ...
CVE-2015-3330
- EPSS 38.96%
- Veröffentlicht 09.06.2015 18:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or p...
CVE-2015-3329
- EPSS 28.15%
- Veröffentlicht 09.06.2015 18:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) ph...
CVE-2015-2922
- EPSS 1.72%
- Veröffentlicht 27.05.2015 10:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value ...
CVE-2015-3812
- EPSS 0.66%
- Veröffentlicht 26.05.2015 15:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple memory leaks in the x11_init_protocol function in epan/dissectors/packet-x11.c in the X11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 allow remote attackers to cause a denial of service (memory consumption) via a cr...
- EPSS 0.21%
- Veröffentlicht 26.05.2015 15:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafte...
CVE-2015-3455
- EPSS 5.01%
- Veröffentlicht 18.05.2015 15:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle atta...
CVE-2015-1351
- EPSS 17.77%
- Veröffentlicht 30.03.2015 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.