Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 78 507

Количество 78 507

ubuntu логотип

CVE-2015-7813

почти 11 лет назад

Xen 4.4.x, 4.5.x, and 4.6.x does not limit the number of printk console messages when reporting unimplemented hypercalls, which allows local guests to cause a denial of service via a sequence of (1) HYPERVISOR_physdev_op hypercalls, which are not properly handled in the do_physdev_op function in arch/arm/physdev.c, or (2) HYPERVISOR_hvm_op hypercalls, which are not properly handled in the do_hvm_op function in arch/arm/hvm.c.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2015-7812

почти 11 лет назад

The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash) via a preemptible hypercall to the multicall interface.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2015-7810

почти 7 лет назад

libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2015-7809

почти 11 лет назад

The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-7805

почти 11 лет назад

Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file.

CVSS2: 9.3
EPSS: Средний
ubuntu логотип

CVE-2015-7804

почти 11 лет назад

Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (uninitialized pointer dereference and application crash) by including the / filename in a .zip PHAR archive.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-7803

почти 11 лет назад

The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a .phar file with a crafted TAR archive entry in which the Link indicator references a file that does not exist.

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2015-7802

больше 10 лет назад

gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2015-7801

больше 10 лет назад

Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2015-7799

почти 11 лет назад

The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2015-7763

почти 11 лет назад

rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conducting a replay attack or (2) sniffing the network.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-7762

почти 11 лет назад

rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conducting a replay attack or (2) sniffing the network.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-7758

больше 10 лет назад

Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .toc extension for the file name, as demonstrated by .thesis.tex.aux.

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2015-7747

больше 6 лет назад

Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by sixteen-stereo-to-eight-mono.c.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2015-7744

больше 10 лет назад

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2015-7724

больше 9 лет назад

AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2015-7723

больше 9 лет назад

AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2015-7718

почти 11 лет назад

mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22278703, a different vulnerability than CVE-2015-6605.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-7717

почти 11 лет назад

mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2015-7716

почти 11 лет назад

libstagefright in Android 5.x before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20721050, a different vulnerability than CVE-2015-3873.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-7813

Xen 4.4.x, 4.5.x, and 4.6.x does not limit the number of printk console messages when reporting unimplemented hypercalls, which allows local guests to cause a denial of service via a sequence of (1) HYPERVISOR_physdev_op hypercalls, which are not properly handled in the do_physdev_op function in arch/arm/physdev.c, or (2) HYPERVISOR_hvm_op hypercalls, which are not properly handled in the do_hvm_op function in arch/arm/hvm.c.

CVSS2: 2.1
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-7812

The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash) via a preemptible hypercall to the multicall interface.

CVSS2: 4.9
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-7810

libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files

CVSS3: 4.7
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2015-7809

The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.

CVSS2: 6.8
3%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-7805

Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file.

CVSS2: 9.3
13%
Средний
почти 11 лет назад
ubuntu логотип
CVE-2015-7804

Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (uninitialized pointer dereference and application crash) by including the / filename in a .zip PHAR archive.

CVSS2: 6.8
9%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-7803

The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a .phar file with a crafted TAR archive entry in which the Link indicator references a file that does not exist.

CVSS2: 6.8
10%
Средний
почти 11 лет назад
ubuntu логотип
CVE-2015-7802

gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.

CVSS3: 5.5
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7801

Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file.

CVSS3: 8.8
5%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7799

The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call.

CVSS2: 4.9
1%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-7763

rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conducting a replay attack or (2) sniffing the network.

CVSS2: 5
2%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-7762

rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conducting a replay attack or (2) sniffing the network.

CVSS2: 5
2%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-7758

Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .toc extension for the file name, as demonstrated by .thesis.tex.aux.

CVSS3: 3.3
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7747

Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by sixteen-stereo-to-eight-mono.c.

CVSS3: 8.8
9%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2015-7744

wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.

CVSS3: 5.9
5%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7724

AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723.

CVSS3: 7.8
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-7723

AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.

CVSS3: 7.8
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-7718

mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22278703, a different vulnerability than CVE-2015-6605.

CVSS2: 5
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-7717

mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.

CVSS2: 9.3
1%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-7716

libstagefright in Android 5.x before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20721050, a different vulnerability than CVE-2015-3873.

CVSS2: 10
2%
Низкий
почти 11 лет назад

Уязвимостей на страницу