Oracle

Linux

228 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 26.05.2015 15:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafte...

  • EPSS 6.47%
  • Veröffentlicht 18.05.2015 15:59:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle atta...

Exploit
  • EPSS 19.13%
  • Veröffentlicht 30.03.2015 10:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • EPSS 0.41%
  • Veröffentlicht 08.03.2015 02:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via...

  • EPSS 0.34%
  • Veröffentlicht 08.03.2015 02:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (out-of-bounds read and applicatio...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 02.03.2015 11:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering u...

  • EPSS 0.06%
  • Veröffentlicht 02.03.2015 11:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.03.2015 11:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.

Exploit
  • EPSS 86.66%
  • Veröffentlicht 28.01.2015 19:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 fu...

  • EPSS 0.62%
  • Veröffentlicht 10.01.2015 02:59:42
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that i...