CVE-2015-4551
- EPSS 9.89%
- Veröffentlicht 10.11.2015 17:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information vi...
- EPSS 3.58%
- Veröffentlicht 09.11.2015 16:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on th...
- EPSS 6.39%
- Veröffentlicht 09.11.2015 03:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field...
CVE-2015-2696
- EPSS 8.28%
- Veröffentlicht 09.11.2015 03:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mis...
- EPSS 4.77%
- Veröffentlicht 09.11.2015 03:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that...
- EPSS 0.47%
- Veröffentlicht 06.11.2015 21:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conductin...
CVE-2015-6855
- EPSS 5.77%
- Veröffentlicht 06.11.2015 21:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_...
CVE-2015-7697
- EPSS 28.5%
- Veröffentlicht 06.11.2015 18:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.
CVE-2015-7696
- EPSS 34.38%
- Veröffentlicht 06.11.2015 18:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value...
CVE-2015-8036
- EPSS 0.92%
- Veröffentlicht 02.11.2015 19:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the se...