CVE-2015-8605
- EPSS 43.44%
- Veröffentlicht 14.01.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
CVE-2015-8607
- EPSS 5.66%
- Veröffentlicht 13.01.2016 15:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted st...
CVE-2016-1232
- EPSS 0.71%
- Veröffentlicht 12.01.2016 20:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.
CVE-2016-1231
- EPSS 0.74%
- Veröffentlicht 12.01.2016 20:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
CVE-2015-1779
- EPSS 5.57%
- Veröffentlicht 12.01.2016 19:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
- EPSS 21.06%
- Veröffentlicht 08.01.2016 21:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.
CVE-2015-8467
- EPSS 1.71%
- Veröffentlicht 29.12.2015 22:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, wh...
CVE-2015-7540
- EPSS 39.6%
- Veröffentlicht 29.12.2015 22:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via cra...
CVE-2015-5299
- EPSS 9.14%
- Veröffentlicht 29.12.2015 22:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote att...
CVE-2015-5296
- EPSS 3.65%
- Veröffentlicht 29.12.2015 22:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-s...