CVE-2015-1572
- EPSS 0.09%
- Veröffentlicht 24.02.2015 15:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an...
CVE-2014-9402
- EPSS 8.7%
- Veröffentlicht 24.02.2015 15:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive ...
- EPSS 5.06%
- Veröffentlicht 24.02.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigge...
- EPSS 89.54%
- Veröffentlicht 24.02.2015 01:59:00
- Zuletzt bearbeitet 09.05.2025 20:15:34
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execu...
CVE-2015-1315
- EPSS 12.1%
- Veröffentlicht 23.02.2015 17:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.
CVE-2015-0247
- EPSS 0.31%
- Veröffentlicht 17.02.2015 15:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
- EPSS 2.11%
- Veröffentlicht 08.02.2015 11:59:36
- Zuletzt bearbeitet 12.04.2025 10:46:40
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
CVE-2014-9674
- EPSS 5.12%
- Veröffentlicht 08.02.2015 11:59:35
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based bu...
CVE-2014-9673
- EPSS 4.22%
- Veröffentlicht 08.02.2015 11:59:34
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac fo...
CVE-2014-9672
- EPSS 4.7%
- Veröffentlicht 08.02.2015 11:59:33
- Zuletzt bearbeitet 12.04.2025 10:46:40
Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac f...