Oracle

Solaris

552 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 7.68%
  • Veröffentlicht 01.10.2015 20:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.

  • EPSS 0.52%
  • Veröffentlicht 25.08.2015 17:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record wi...

  • EPSS 0.57%
  • Veröffentlicht 24.08.2015 23:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.7 does not prevent the conflicting use of a table for both IPv4 and IPv6 addresses, which allows remote attackers t...

  • EPSS 0.68%
  • Veröffentlicht 24.08.2015 23:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application cras...

  • EPSS 0.57%
  • Veröffentlicht 24.08.2015 23:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5.c in the OpenFlow dissector in Wireshark 1.12.x before 1.12.7 does not validate a certain offset value, which allows remote attackers to cause a denial of service (infini...

  • EPSS 0.66%
  • Veröffentlicht 24.08.2015 23:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The dissect_wa_payload function in epan/dissectors/packet-waveagent.c in the WaveAgent dissector in Wireshark 1.12.x before 1.12.7 mishandles large tag values, which allows remote attackers to cause a denial of service (application crash) via a craft...

  • EPSS 0.38%
  • Veröffentlicht 24.08.2015 23:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC/MAC dissector in Wireshark 1.12.x before 1.12.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

  • EPSS 0.8%
  • Veröffentlicht 24.08.2015 23:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of servi...

  • EPSS 0.66%
  • Veröffentlicht 24.08.2015 23:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The dissector-table implementation in epan/packet.c in Wireshark 1.12.x before 1.12.7 mishandles table searches for empty strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the (1)...

  • EPSS 0.57%
  • Veröffentlicht 24.08.2015 23:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_block.c in the wmem block allocator in the memory manager in Wireshark 1.12.x before 1.12.7 does not properly consider a certain case of multiple realloc operations that restore a m...