Количество 25 355
Количество 25 355
CVE-2015-7511
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.
CVE-2015-7504
CVE-2015-7309
The theme editor in Bolt allows remote authenticated users to execute arbitrary code by renaming a crafted file
CVE-2015-6749
CVE-2015-6117
CVE-2015-5741
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields.
CVE-2015-5738
CVE-2015-5157
arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution which might allow local users to gain privileges by triggering an NMI.
CVE-2015-4646
CVE-2015-4645
CVE-2015-3717
CVE-2015-3631
CVE-2015-3630
CVE-2015-3627
CVE-2015-3416
The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.
CVE-2015-3310
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.
CVE-2015-3276
CVE-2015-2987
CVE-2015-2704
realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf
CVE-2015-2158
Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2015-7511 Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations. | 0% Низкий | 11 месяцев назад | ||
CVSS3: 8.8 | 1% Низкий | почти 6 лет назад | ||
CVE-2015-7309 The theme editor in Bolt allows remote authenticated users to execute arbitrary code by renaming a crafted file | 39% Средний | 10 месяцев назад | ||
4% Низкий | больше 4 лет назад | |||
7% Низкий | больше 10 лет назад | |||
CVE-2015-5741 The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields. | 3% Низкий | 6 месяцев назад | ||
CVSS3: 7.5 | 2% Низкий | почти 6 лет назад | ||
CVE-2015-5157 arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution which might allow local users to gain privileges by triggering an NMI. | 1% Низкий | 6 месяцев назад | ||
CVSS3: 7.5 | 7% Низкий | около 5 лет назад | ||
CVSS3: 5.5 | 3% Низкий | около 5 лет назад | ||
5% Низкий | почти 6 лет назад | |||
1% Низкий | около 5 лет назад | |||
1% Низкий | около 5 лет назад | |||
1% Низкий | около 5 лет назад | |||
CVE-2015-3416 The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement. | 6% Низкий | 11 месяцев назад | ||
CVE-2015-3310 Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server. | 5% Низкий | около 1 года назад | ||
CVSS3: 7.5 | 5% Низкий | почти 6 лет назад | ||
1% Низкий | почти 6 лет назад | |||
CVE-2015-2704 realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf | 3% Низкий | 10 месяцев назад | ||
CVE-2015-2158 Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service | CVSS3: 7.8 | 3% Низкий | больше 1 года назад |
Уязвимостей на страницу