CVE-2015-6855
- EPSS 5.77%
- Veröffentlicht 06.11.2015 21:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_...
CVE-2015-5225
- EPSS 0.17%
- Veröffentlicht 06.11.2015 21:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via ...
CVE-2015-8036
- EPSS 0.92%
- Veröffentlicht 02.11.2015 19:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the se...
CVE-2015-5291
- EPSS 1.7%
- Veröffentlicht 02.11.2015 19:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a lon...
CVE-2015-5262
- EPSS 0.92%
- Veröffentlicht 27.10.2015 16:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang)...
CVE-2015-4625
- EPSS 0.11%
- Veröffentlicht 26.10.2015 19:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a duplicate cookie value.
CVE-2015-4913
- EPSS 0.39%
- Veröffentlicht 22.10.2015 00:00:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.
CVE-2015-4895
- EPSS 0.39%
- Veröffentlicht 21.10.2015 23:59:55
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
CVE-2015-4879
- EPSS 0.6%
- Veröffentlicht 21.10.2015 23:59:42
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to DML.
- EPSS 19.91%
- Veröffentlicht 21.10.2015 23:59:34
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.