CVE-2015-0239
- EPSS 0.1%
- Veröffentlicht 02.03.2015 11:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering u...
CVE-2014-9644
- EPSS 0.06%
- Veröffentlicht 02.03.2015 11:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) ...
- EPSS 2.45%
- Veröffentlicht 02.03.2015 11:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass in...
CVE-2013-7421
- EPSS 0.04%
- Veröffentlicht 02.03.2015 11:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.
- EPSS 0.89%
- Veröffentlicht 28.02.2015 02:59:35
- Zuletzt bearbeitet 06.05.2026 22:30:45
checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.
CVE-2015-1414
- EPSS 0.56%
- Veröffentlicht 27.02.2015 15:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of...
CVE-2015-1572
- EPSS 0.16%
- Veröffentlicht 24.02.2015 15:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an...
CVE-2015-2047
- EPSS 0.77%
- Veröffentlicht 23.02.2015 17:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.18, when configured for the frontend, allows remote attackers to bypass authentication via a password that is casted to an empty va...
CVE-2015-1592
- EPSS 81.05%
- Veröffentlicht 19.02.2015 15:59:16
- Zuletzt bearbeitet 06.05.2026 22:30:45
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attackers to include and execute arbitrary local Perl files and possibly exe...
CVE-2015-0247
- EPSS 0.4%
- Veröffentlicht 17.02.2015 15:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.