- EPSS 2.85%
- Veröffentlicht 14.09.2015 20:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as demonstrated by 8#garbage.
CVE-2015-5200
- EPSS 0.09%
- Veröffentlicht 08.09.2015 15:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.
CVE-2015-5199
- EPSS 0.05%
- Veröffentlicht 08.09.2015 15:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in dlopen in libvdpau before 1.1.1 allows local users to gain privileges via the VDPAU_DRIVER environment variable.
CVE-2015-5198
- EPSS 0.09%
- Veröffentlicht 08.09.2015 15:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privileges via unspecified vectors, related to the VDPAU_DRIVER_PATH environment variable.
CVE-2015-6826
- EPSS 0.89%
- Veröffentlicht 06.09.2015 02:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified o...
CVE-2015-6824
- EPSS 0.89%
- Veröffentlicht 06.09.2015 02:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does not initialize certain pixbuf data structures, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impa...
CVE-2015-6820
- EPSS 0.89%
- Veröffentlicht 06.09.2015 02:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax element before proceeding with Spectral Band Replication calculations, which allows remote attackers to cause a denial of service (...
CVE-2015-6818
- EPSS 0.89%
- Veröffentlicht 06.09.2015 02:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (aka image header) chunk in a PNG image, which allows remote attackers to cause a denial of service (out-of-bounds array access) or p...
CVE-2015-3308
- EPSS 1.39%
- Veröffentlicht 02.09.2015 14:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
- EPSS 0.41%
- Veröffentlicht 01.09.2015 14:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.