CVE-2015-3194
- EPSS 58.14%
- Veröffentlicht 06.12.2015 20:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function p...
CVE-2015-6764
- EPSS 13.88%
- Veröffentlicht 06.12.2015 01:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service ...
CVE-2015-0859
- EPSS 2.83%
- Veröffentlicht 03.12.2015 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes arguments to smokeping_cgi, which allows remote attackers to execute arbitra...
- EPSS 2.01%
- Veröffentlicht 24.11.2015 20:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which trigge...
CVE-2015-7984
- EPSS 1.13%
- Veröffentlicht 19.11.2015 20:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of administrators for requests that...
CVE-2015-8035
- EPSS 1.08%
- Veröffentlicht 18.11.2015 16:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
CVE-2015-7942
- EPSS 1.46%
- Veröffentlicht 18.11.2015 16:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via...
CVE-2015-8104
- EPSS 0.33%
- Veröffentlicht 16.11.2015 11:59:12
- Zuletzt bearbeitet 23.04.2025 16:15:20
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.
CVE-2015-7312
- EPSS 0.04%
- Veröffentlicht 16.11.2015 11:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.patch patches for the Linux kernel 3.x and 4.x allow local users to cause a denial of service (use-after-free and BUG) or possibly gain privileges via a ...
CVE-2015-5307
- EPSS 0.1%
- Veröffentlicht 16.11.2015 11:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.