CVE-2015-8241
- EPSS 1.75%
- Veröffentlicht 15.12.2015 21:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML dat...
- EPSS 4.25%
- Veröffentlicht 15.12.2015 21:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
- EPSS 2.95%
- Veröffentlicht 15.12.2015 21:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
- EPSS 3.44%
- Veröffentlicht 15.12.2015 21:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
- EPSS 3.44%
- Veröffentlicht 15.12.2015 21:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.
CVE-2015-5312
- EPSS 1.99%
- Veröffentlicht 15.12.2015 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerab...
CVE-2015-1344
- EPSS 0.04%
- Veröffentlicht 07.12.2015 20:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to the tasks file.
CVE-2015-1342
- EPSS 0.06%
- Veröffentlicht 07.12.2015 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
LXCFS before 0.12 does not properly enforce directory escapes, which might allow local users to gain privileges by (1) querying or (2) updating a cgroup.
CVE-2015-3196
- EPSS 10.26%
- Veröffentlicht 06.12.2015 20:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (...
CVE-2015-3195
- EPSS 3.44%
- Veröffentlicht 06.12.2015 20:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to ob...