CVE-2015-2752
- EPSS 0.12%
- Veröffentlicht 01.04.2015 14:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the devi...
CVE-2015-2751
- EPSS 1.43%
- Veröffentlicht 01.04.2015 14:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host lock) via unspecified domctl operations.
- EPSS 1.18%
- Veröffentlicht 30.03.2015 14:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user th...
- EPSS 36.47%
- Veröffentlicht 30.03.2015 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.
- EPSS 1.69%
- Veröffentlicht 30.03.2015 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
CVE-2015-2331
- EPSS 42.71%
- Veröffentlicht 30.03.2015 10:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial ...
CVE-2015-2157
- EPSS 0.27%
- Veröffentlicht 27.03.2015 14:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.
CVE-2015-2317
- EPSS 4.67%
- Veröffentlicht 25.03.2015 14:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a con...
- EPSS 2%
- Veröffentlicht 25.03.2015 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the ...
- EPSS 1.51%
- Veröffentlicht 25.03.2015 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.