CVE-2015-5345
- EPSS 49.88%
- Veröffentlicht 25.02.2016 01:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence o...
CVE-2015-5174
- EPSS 4.8%
- Veröffentlicht 25.02.2016 01:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.....
CVE-2015-8805
- EPSS 1.2%
- Veröffentlicht 23.02.2016 19:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown...
CVE-2015-8804
- EPSS 11.88%
- Veröffentlicht 23.02.2016 19:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.
CVE-2015-8803
- EPSS 12.34%
- Veröffentlicht 23.02.2016 19:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown...
CVE-2016-0795
- EPSS 0.55%
- Veröffentlicht 18.02.2016 21:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.
CVE-2016-0794
- EPSS 0.49%
- Veröffentlicht 18.02.2016 21:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
CVE-2015-7547
- EPSS 93.95%
- Veröffentlicht 18.02.2016 21:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrar...
CVE-2016-0773
- EPSS 10.87%
- Veröffentlicht 17.02.2016 15:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a ...
- EPSS 0.51%
- Veröffentlicht 17.02.2016 15:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privilege...