CVE-2015-8126
- EPSS 5.76%
- Veröffentlicht 13.11.2015 03:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a den...
CVE-2015-8025
- EPSS 0.07%
- Veröffentlicht 10.11.2015 17:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
driver/subprocs.c in XScreenSaver before 5.34 does not properly perform an internal consistency check, which allows physically proximate attackers to bypass the lock screen by hot swapping monitors.
CVE-2015-5214
- EPSS 29.52%
- Veröffentlicht 10.11.2015 17:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via an index to a non-existent bookmark in a DOC...
CVE-2015-5213
- EPSS 14.17%
- Veröffentlicht 10.11.2015 17:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a bu...
CVE-2015-5212
- EPSS 43.03%
- Veröffentlicht 10.11.2015 17:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and applica...
CVE-2015-4551
- EPSS 7.75%
- Veröffentlicht 10.11.2015 17:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information vi...
- EPSS 5.45%
- Veröffentlicht 09.11.2015 03:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field...
CVE-2015-2696
- EPSS 10.77%
- Veröffentlicht 09.11.2015 03:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mis...
- EPSS 4.58%
- Veröffentlicht 09.11.2015 03:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that...
CVE-2015-6855
- EPSS 4.25%
- Veröffentlicht 06.11.2015 21:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_...