CVE-2015-5146
- EPSS 1.45%
- Veröffentlicht 24.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash...
- EPSS 93.79%
- Veröffentlicht 23.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace looku...
CVE-2015-5258
- EPSS 0.17%
- Veröffentlicht 22.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.
CVE-2017-12843
- EPSS 0.28%
- Veröffentlicht 22.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
CVE-2015-1783
- EPSS 1.06%
- Veröffentlicht 11.08.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors.
CVE-2015-6816
- EPSS 2.11%
- Veröffentlicht 09.08.2017 18:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
ganglia-web before 3.7.1 allows remote attackers to bypass authentication.
CVE-2017-11368
- EPSS 0.31%
- Veröffentlicht 09.08.2017 18:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
CVE-2015-3405
- EPSS 6.21%
- Veröffentlicht 09.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remot...
CVE-2015-5203
- EPSS 0.38%
- Veröffentlicht 02.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
CVE-2015-5221
- EPSS 0.23%
- Veröffentlicht 25.07.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.