CVE-2015-8035
- EPSS 1.01%
- Veröffentlicht 18.11.2015 16:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.
- EPSS 0.8%
- Veröffentlicht 18.11.2015 16:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success messag...
CVE-2015-7942
- EPSS 1.01%
- Veröffentlicht 18.11.2015 16:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via...
CVE-2015-7941
- EPSS 0.43%
- Veröffentlicht 18.11.2015 16:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSect...
CVE-2015-8222
- EPSS 0.12%
- Veröffentlicht 17.11.2015 15:59:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.
- EPSS 0.91%
- Veröffentlicht 17.11.2015 15:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215.
CVE-2015-8104
- EPSS 0.34%
- Veröffentlicht 16.11.2015 11:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.
CVE-2015-7312
- EPSS 0.04%
- Veröffentlicht 16.11.2015 11:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.patch patches for the Linux kernel 3.x and 4.x allow local users to cause a denial of service (use-after-free and BUG) or possibly gain privileges via a ...
CVE-2015-5307
- EPSS 0.1%
- Veröffentlicht 16.11.2015 11:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.
CVE-2015-2925
- EPSS 0.75%
- Veröffentlicht 16.11.2015 11:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a...