- EPSS 0.19%
- Veröffentlicht 26.05.2015 15:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafte...
CVE-2015-3455
- EPSS 6.47%
- Veröffentlicht 18.05.2015 15:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle atta...
CVE-2015-1351
- EPSS 19.13%
- Veröffentlicht 30.03.2015 10:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
- EPSS 0.41%
- Veröffentlicht 08.03.2015 02:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via...
- EPSS 0.34%
- Veröffentlicht 08.03.2015 02:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (out-of-bounds read and applicatio...
CVE-2015-0239
- EPSS 0.1%
- Veröffentlicht 02.03.2015 11:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering u...
CVE-2014-9644
- EPSS 0.06%
- Veröffentlicht 02.03.2015 11:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) ...
CVE-2013-7421
- EPSS 0.04%
- Veröffentlicht 02.03.2015 11:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.
- EPSS 86.66%
- Veröffentlicht 28.01.2015 19:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 fu...
- EPSS 0.62%
- Veröffentlicht 10.01.2015 02:59:42
- Zuletzt bearbeitet 06.05.2026 22:30:45
Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that i...