CVE-2015-8557
- EPSS 7%
- Veröffentlicht 08.01.2016 20:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
CVE-2015-8467
- EPSS 1.75%
- Veröffentlicht 29.12.2015 22:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, wh...
CVE-2015-7540
- EPSS 43.3%
- Veröffentlicht 29.12.2015 22:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via cra...
CVE-2015-5299
- EPSS 8.49%
- Veröffentlicht 29.12.2015 22:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote att...
CVE-2015-5296
- EPSS 3.37%
- Veröffentlicht 29.12.2015 22:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-s...
CVE-2015-5252
- EPSS 17.33%
- Veröffentlicht 29.12.2015 22:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points o...
CVE-2015-8327
- EPSS 19.46%
- Veröffentlicht 17.12.2015 19:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
CVE-2015-5277
- EPSS 0.1%
- Veröffentlicht 17.12.2015 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS...
- EPSS 0.33%
- Veröffentlicht 15.12.2015 21:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds ...
CVE-2015-8242
- EPSS 1.66%
- Veröffentlicht 15.12.2015 21:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive informati...