Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 78 507

Количество 78 507

ubuntu логотип

CVE-2015-8325

больше 10 лет назад

The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2015-8324

больше 10 лет назад

The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted USB device, related to the ext4_fill_super function.

CVSS3: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2015-8317

почти 11 лет назад

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-8316

около 9 лет назад

Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2015-8313

больше 6 лет назад

GnuTLS incorrectly validates the first byte of padding in CBC modes

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2015-8312

больше 10 лет назад

Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system crash) via a pioctl with an input buffer size of 4096 bytes.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2015-8308

около 9 лет назад

LXDM before 0.5.2 did not start X server with -auth, which allows local users to bypass authentication with X connections.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2015-8272

больше 9 лет назад

RTMPDump 2.4 allows remote attackers to trigger a denial of service (NULL pointer dereference and process crash).

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8271

больше 9 лет назад

The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2015-8270

больше 9 лет назад

The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a denial of service (invalid pointer dereference and process crash).

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8242

почти 11 лет назад

The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2015-8241

почти 11 лет назад

The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2015-8239

почти 9 лет назад

The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2015-8235

больше 9 лет назад

Directory traversal vulnerability in Spiffy before 5.4.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8234

больше 9 лет назад

The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8222

почти 11 лет назад

The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2015-8219

почти 11 лет назад

The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-value constraints on tile coordinates, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8218

почти 11 лет назад

The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted CCITT FAX data.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-8217

почти 11 лет назад

The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indicator, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted High Efficiency Video Coding (HEVC) data.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-8216

почти 11 лет назад

The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8.2 omits certain width and height checks, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted MJPEG data.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-8325

The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.

CVSS3: 7.8
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8324

The ext4 implementation in the Linux kernel before 2.6.34 does not properly track the initialization of certain data structures, which allows physically proximate attackers to cause a denial of service (NULL pointer dereference and panic) via a crafted USB device, related to the ext4_fill_super function.

CVSS3: 4.6
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8317

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.

CVSS2: 5
6%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-8316

Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address.

CVSS3: 5.9
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2015-8313

GnuTLS incorrectly validates the first byte of padding in CBC modes

CVSS3: 5.9
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2015-8312

Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system crash) via a pioctl with an input buffer size of 4096 bytes.

CVSS3: 7.8
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-8308

LXDM before 0.5.2 did not start X server with -auth, which allows local users to bypass authentication with X connections.

CVSS3: 7.8
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2015-8272

RTMPDump 2.4 allows remote attackers to trigger a denial of service (NULL pointer dereference and process crash).

CVSS3: 6.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8271

The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.

CVSS3: 9.8
6%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8270

The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a denial of service (invalid pointer dereference and process crash).

CVSS3: 7.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8242

The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.

CVSS2: 5.8
4%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-8241

The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.

CVSS2: 6.4
5%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-8239

The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.

CVSS3: 7
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2015-8235

Directory traversal vulnerability in Spiffy before 5.4.

CVSS3: 7.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8234

The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.

CVSS3: 5.5
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-8222

The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.

CVSS2: 4.6
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-8219

The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-value constraints on tile coordinates, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data.

CVSS2: 7.5
2%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-8218

The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted CCITT FAX data.

CVSS2: 6.8
2%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-8217

The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indicator, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted High Efficiency Video Coding (HEVC) data.

CVSS2: 7.5
2%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-8216

The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8.2 omits certain width and height checks, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted MJPEG data.

CVSS2: 7.5
2%
Низкий
почти 11 лет назад

Уязвимостей на страницу