CVE-2015-2317
- EPSS 4.67%
- Veröffentlicht 25.03.2015 14:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a con...
- EPSS 2%
- Veröffentlicht 25.03.2015 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the ...
CVE-2015-2265
- EPSS 5.8%
- Veröffentlicht 24.03.2015 17:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of ...
CVE-2015-0250
- EPSS 1.08%
- Veröffentlicht 24.03.2015 17:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.
CVE-2015-1803
- EPSS 1.69%
- Veröffentlicht 20.03.2015 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer der...
CVE-2015-2296
- EPSS 1.95%
- Veröffentlicht 18.03.2015 16:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
- EPSS 10.87%
- Veröffentlicht 16.03.2015 10:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by tri...
CVE-2014-8159
- EPSS 0.08%
- Veröffentlicht 16.03.2015 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary p...
CVE-2015-2304
- EPSS 3.52%
- Veröffentlicht 15.03.2015 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
CVE-2015-0254
- EPSS 3.81%
- Veröffentlicht 09.03.2015 14:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.