CVE-2015-8386
- EPSS 7.13%
- Veröffentlicht 02.12.2015 01:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expr...
CVE-2015-8383
- EPSS 4.44%
- Veröffentlicht 02.12.2015 01:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript ...
CVE-2015-8380
- EPSS 1.24%
- Veröffentlicht 02.12.2015 01:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regul...
CVE-2015-7496
- EPSS 0.08%
- Veröffentlicht 24.11.2015 20:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.
CVE-2015-0856
- EPSS 0.17%
- Veröffentlicht 24.11.2015 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.
CVE-2015-8126
- EPSS 6.44%
- Veröffentlicht 13.11.2015 03:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a den...
- EPSS 3.58%
- Veröffentlicht 09.11.2015 16:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on th...
CVE-2015-6855
- EPSS 5.77%
- Veröffentlicht 06.11.2015 21:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_...
CVE-2015-5225
- EPSS 0.17%
- Veröffentlicht 06.11.2015 21:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via ...
CVE-2015-8036
- EPSS 0.92%
- Veröffentlicht 02.11.2015 19:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the se...