CVE-2015-2696
- EPSS 10.77%
- Veröffentlicht 09.11.2015 03:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mis...
- EPSS 4.58%
- Veröffentlicht 09.11.2015 03:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that...
- EPSS 0.47%
- Veröffentlicht 06.11.2015 21:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conductin...
CVE-2015-6855
- EPSS 4.25%
- Veröffentlicht 06.11.2015 21:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_...
CVE-2015-7697
- EPSS 32.05%
- Veröffentlicht 06.11.2015 18:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.
CVE-2015-7696
- EPSS 33.92%
- Veröffentlicht 06.11.2015 18:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value...
CVE-2015-8036
- EPSS 1.45%
- Veröffentlicht 02.11.2015 19:59:16
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the se...
CVE-2015-6031
- EPSS 3.23%
- Veröffentlicht 02.11.2015 19:59:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversiz...
CVE-2015-5291
- EPSS 2.05%
- Veröffentlicht 02.11.2015 19:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a lon...
CVE-2015-5289
- EPSS 6.57%
- Veröffentlicht 26.10.2015 14:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (...