CVE-2015-6245
- EPSS 0.38%
- Veröffentlicht 24.08.2015 23:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC/MAC dissector in Wireshark 1.12.x before 1.12.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
CVE-2015-6244
- EPSS 0.8%
- Veröffentlicht 24.08.2015 23:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of servi...
CVE-2015-6243
- EPSS 0.66%
- Veröffentlicht 24.08.2015 23:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dissector-table implementation in epan/packet.c in Wireshark 1.12.x before 1.12.7 mishandles table searches for empty strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the (1)...
CVE-2015-6242
- EPSS 0.57%
- Veröffentlicht 24.08.2015 23:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_block.c in the wmem block allocator in the memory manager in Wireshark 1.12.x before 1.12.7 does not properly consider a certain case of multiple realloc operations that restore a m...
CVE-2015-6241
- EPSS 0.57%
- Veröffentlicht 24.08.2015 23:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree implementation in Wireshark 1.12.x before 1.12.7 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote attacker...
- EPSS 4.37%
- Veröffentlicht 24.08.2015 14:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote...
- EPSS 5.34%
- Veröffentlicht 24.08.2015 14:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions allows remote attackers to cause a denial of service (session store consumption or session record remova...
CVE-2015-3219
- EPSS 0.41%
- Veröffentlicht 20.08.2015 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015.1.x before 2015.1.1 allows remote attackers to inject arbitrary web script or HTML via the description parame...
CVE-2015-4496
- EPSS 2.04%
- Veröffentlicht 16.08.2015 01:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.
CVE-2015-4493
- EPSS 10.19%
- Veröffentlicht 16.08.2015 01:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an invalid size field in an esds c...