CVE-2015-3214
- EPSS 1.47%
- Published 31.08.2015 10:59:07
- Last modified 12.04.2025 10:46:40
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an inva...
CVE-2015-6525
- EPSS 1.07%
- Published 24.08.2015 14:59:14
- Last modified 12.04.2025 10:46:40
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1)...
- EPSS 2.79%
- Published 24.08.2015 14:59:12
- Last modified 12.04.2025 10:46:40
conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote attackers to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or (3) ICMPv6 packet.
- EPSS 6.69%
- Published 24.08.2015 14:59:10
- Last modified 12.04.2025 10:46:40
Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.
CVE-2014-6272
- EPSS 1.09%
- Published 24.08.2015 14:59:01
- Last modified 12.04.2025 10:46:40
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely la...
CVE-2015-3219
- EPSS 0.41%
- Published 20.08.2015 20:59:00
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015.1.x before 2015.1.1 allows remote attackers to inject arbitrary web script or HTML via the description parame...
- EPSS 1.4%
- Published 16.08.2015 01:59:00
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...
- EPSS 2.91%
- Published 14.08.2015 18:59:03
- Last modified 12.04.2025 10:46:40
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
CVE-2015-5165
- EPSS 10.86%
- Published 12.08.2015 14:59:24
- Last modified 12.04.2025 10:46:40
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
CVE-2015-5523
- EPSS 5.03%
- Published 11.08.2015 14:59:15
- Last modified 12.04.2025 10:46:40
The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.