CVE-2015-1803
- EPSS 1.69%
- Veröffentlicht 20.03.2015 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer der...
CVE-2015-1420
- EPSS 0.03%
- Veröffentlicht 16.03.2015 10:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of ...
- EPSS 10.87%
- Veröffentlicht 16.03.2015 10:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by tri...
CVE-2014-8159
- EPSS 0.08%
- Veröffentlicht 16.03.2015 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary p...
CVE-2015-1782
- EPSS 4.68%
- Veröffentlicht 13.03.2015 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.
CVE-2015-2151
- EPSS 0.24%
- Veröffentlicht 12.03.2015 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly...
CVE-2015-2045
- EPSS 0.08%
- Veröffentlicht 12.03.2015 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data structures, which allows local guest users to obtain sensitive information via unspecified vectors.
- EPSS 0.39%
- Veröffentlicht 09.03.2015 14:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors.
CVE-2014-9472
- EPSS 0.88%
- Veröffentlicht 09.03.2015 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email.
- EPSS 3.29%
- Veröffentlicht 08.03.2015 02:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted length...