- EPSS 7.89%
- Published 09.06.2015 14:59:07
- Last modified 12.04.2025 10:46:40
Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
- EPSS 8.42%
- Published 07.06.2015 23:59:03
- Last modified 12.04.2025 10:46:40
The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attacker...
CVE-2015-4106
- EPSS 0.09%
- Published 03.06.2015 20:59:09
- Last modified 12.04.2025 10:46:40
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly ha...
CVE-2015-4047
- EPSS 3.59%
- Published 29.05.2015 15:59:19
- Last modified 12.04.2025 10:46:40
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
CVE-2015-3165
- EPSS 8.53%
- Published 28.05.2015 14:59:06
- Last modified 12.04.2025 10:46:40
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the auth...
CVE-2015-3339
- EPSS 0.03%
- Published 27.05.2015 10:59:11
- Last modified 12.04.2025 10:46:40
Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but t...
CVE-2015-3332
- EPSS 0.12%
- Published 27.05.2015 10:59:08
- Last modified 12.04.2025 10:46:40
A certain backport in the TCP Fast Open implementation for the Linux kernel before 3.18 does not properly maintain a count value, which allow local users to cause a denial of service (system crash) via the Fast Open feature, as demonstrated by visiti...
CVE-2015-3331
- EPSS 4.03%
- Published 27.05.2015 10:59:07
- Last modified 12.04.2025 10:46:40
The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attackers to cause a denial of serv...
CVE-2015-2830
- EPSS 0.04%
- Published 27.05.2015 10:59:06
- Last modified 12.04.2025 10:46:40
arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the...
CVE-2015-2922
- EPSS 1.72%
- Published 27.05.2015 10:59:06
- Last modified 12.04.2025 10:46:40
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value ...