CVE-2015-8767
- EPSS 0.12%
- Veröffentlicht 08.02.2016 03:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.
CVE-2015-7513
- EPSS 0.08%
- Veröffentlicht 08.02.2016 03:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_v...
CVE-2015-8783
- EPSS 0.66%
- Veröffentlicht 01.02.2016 21:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.
CVE-2015-8782
- EPSS 1.56%
- Veröffentlicht 01.02.2016 21:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a different vulnerability than CVE-2015-8781.
CVE-2015-8781
- EPSS 2.09%
- Veröffentlicht 01.02.2016 21:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of samples per pixel in a LogL compressed TIFF image, a different vulnerability than CVE-2015-8782.
CVE-2016-0755
- EPSS 1.03%
- Veröffentlicht 29.01.2016 20:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.
CVE-2016-2047
- EPSS 2.69%
- Veröffentlicht 27.01.2016 20:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly ver...
CVE-2015-7974
- EPSS 3.67%
- Veröffentlicht 26.01.2016 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
CVE-2016-1572
- EPSS 0.05%
- Veröffentlicht 22.01.2016 15:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
- EPSS 0.47%
- Veröffentlicht 21.01.2016 03:02:39
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.