- EPSS 2.4%
- Veröffentlicht 24.06.2015 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, a...
- EPSS 75.52%
- Veröffentlicht 09.06.2015 18:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form ...
CVE-2015-3330
- EPSS 38.96%
- Veröffentlicht 09.06.2015 18:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or p...
CVE-2015-3329
- EPSS 28.15%
- Veröffentlicht 09.06.2015 18:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) ph...
CVE-2015-3200
- EPSS 20.03%
- Veröffentlicht 09.06.2015 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.
CVE-2015-2922
- EPSS 1.72%
- Veröffentlicht 27.05.2015 10:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value ...
- EPSS 0.19%
- Veröffentlicht 26.05.2015 15:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 interpret a zero value as a length rather than an error ...
CVE-2015-3812
- EPSS 0.66%
- Veröffentlicht 26.05.2015 15:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple memory leaks in the x11_init_protocol function in epan/dissectors/packet-x11.c in the X11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 allow remote attackers to cause a denial of service (memory consumption) via a cr...
- EPSS 0.21%
- Veröffentlicht 26.05.2015 15:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafte...
CVE-2015-3988
- EPSS 0.35%
- Veröffentlicht 19.05.2015 18:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate.