CVE-2015-1851
- EPSS 0.49%
- Veröffentlicht 25.06.2015 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.
CVE-2015-3395
- EPSS 0.79%
- Veröffentlicht 16.06.2015 16:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via...
CVE-2015-3209
- EPSS 20.57%
- Veröffentlicht 15.06.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
CVE-2015-4171
- EPSS 1.01%
- Veröffentlicht 10.06.2015 18:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is...
CVE-2015-3905
- EPSS 4.72%
- Veröffentlicht 08.06.2015 14:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
CVE-2015-4004
- EPSS 4.32%
- Veröffentlicht 07.06.2015 23:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and syste...
- EPSS 3.72%
- Veröffentlicht 07.06.2015 23:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 does not ensure that certain length values are sufficiently large, which allows remote attackers to cause a denial of service (system crash or large loop) or po...
CVE-2015-4106
- EPSS 0.09%
- Veröffentlicht 03.06.2015 20:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly ha...
CVE-2015-4047
- EPSS 3.59%
- Veröffentlicht 29.05.2015 15:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
CVE-2015-0847
- EPSS 2.55%
- Veröffentlicht 29.05.2015 15:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of service (deadlock) via unspecified vectors.