Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 78 507

Количество 78 507

ubuntu логотип

CVE-2015-8776

больше 10 лет назад

The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2015-8771

больше 9 лет назад

The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2015-8770

больше 10 лет назад

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2015-8768

больше 9 лет назад

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2015-8767

больше 10 лет назад

net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.

CVSS3: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2015-8764

больше 9 лет назад

Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2015-8763

больше 9 лет назад

The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message, which triggers an out-of-bounds read.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2015-8762

больше 9 лет назад

The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packet.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2015-8760

больше 10 лет назад

The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing."

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2015-8759

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated editors to inject arbitrary web script or HTML via a link field.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2015-8758

больше 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in unspecified frontend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2015-8757

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to extension data during an extension installation.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2015-8756

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in TYPO3 6.2.x before 6.2.16 allows remote authenticated editors to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2015-8755

больше 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2015-8751

больше 6 лет назад

Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2015-8750

больше 9 лет назад

libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked NOBITS in an ELF file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8749

больше 10 лет назад

The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2015-8748

больше 10 лет назад

Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user name, as demonstrated by ".*".

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2015-8747

больше 10 лет назад

The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name.

CVSS3: 10
EPSS: Низкий
ubuntu логотип

CVE-2015-8746

больше 10 лет назад

fs/nfs/nfs4proc.c in the NFS client in the Linux kernel before 4.2.2 does not properly initialize memory for migration recovery operations, which allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) via crafted network traffic.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-8776

The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.

CVSS3: 9.1
5%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8771

The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.

CVSS3: 9.8
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8770

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.

CVSS3: 7.5
22%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2015-8768

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.

CVSS3: 9.8
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8767

net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.

CVSS3: 6.2
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8764

Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.

CVSS3: 8.1
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8763

The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message, which triggers an out-of-bounds read.

CVSS3: 8.1
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8762

The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packet.

CVSS3: 5.9
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8760

The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing."

CVSS3: 6.1
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8759

Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated editors to inject arbitrary web script or HTML via a link field.

CVSS3: 5.4
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8758

Multiple cross-site scripting (XSS) vulnerabilities in unspecified frontend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.

CVSS3: 5.4
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8757

Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to extension data during an extension installation.

CVSS3: 6.1
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8756

Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in TYPO3 6.2.x before 6.2.16 allows remote authenticated editors to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 5.4
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8755

Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.

CVSS3: 5.4
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8751

Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2015-8750

libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked NOBITS in an ELF file.

CVSS3: 6.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8749

The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.

CVSS3: 5.9
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8748

Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user name, as demonstrated by ".*".

CVSS3: 5.3
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8747

The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name.

CVSS3: 10
3%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8746

fs/nfs/nfs4proc.c in the NFS client in the Linux kernel before 4.2.2 does not properly initialize memory for migration recovery operations, which allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) via crafted network traffic.

CVSS3: 7.5
3%
Низкий
больше 10 лет назад

Уязвимостей на страницу