CVE-2015-1781
- EPSS 7.3%
- Veröffentlicht 28.09.2015 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS respo...
- EPSS 2.36%
- Veröffentlicht 14.09.2015 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
- EPSS 0.63%
- Veröffentlicht 02.09.2015 10:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.
CVE-2015-5706
- EPSS 0.06%
- Veröffentlicht 31.08.2015 10:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that lev...
CVE-2015-5364
- EPSS 21.23%
- Veröffentlicht 31.08.2015 10:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect checksums within a UDP packet f...
CVE-2015-3214
- EPSS 1.59%
- Veröffentlicht 31.08.2015 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an inva...
CVE-2015-6525
- EPSS 1.07%
- Veröffentlicht 24.08.2015 14:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1)...
- EPSS 2.79%
- Veröffentlicht 24.08.2015 14:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote attackers to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or (3) ICMPv6 packet.
- EPSS 6.69%
- Veröffentlicht 24.08.2015 14:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.
CVE-2014-6272
- EPSS 1.09%
- Veröffentlicht 24.08.2015 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely la...