Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 78 507

Количество 78 507

ubuntu логотип

CVE-2015-7543

около 9 лет назад

aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2015-7542

почти 7 лет назад

A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2015-7540

больше 10 лет назад

The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-7539

больше 10 лет назад

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-7538

больше 10 лет назад

Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2015-7537

больше 10 лет назад

Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2015-7536

больше 10 лет назад

Cross-site scripting (XSS) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to workspaces and archived artifacts.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2015-7529

почти 9 лет назад

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2015-7519

больше 10 лет назад

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2015-7515

больше 10 лет назад

The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device that lacks endpoints.

CVSS3: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2015-7514

больше 9 лет назад

OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2015-7513

больше 10 лет назад

arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_vm_ioctl_set_pit and kvm_vm_ioctl_set_pit2 functions.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2015-7512

больше 10 лет назад

Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.

CVSS3: 9
EPSS: Низкий
ubuntu логотип

CVE-2015-7511

больше 10 лет назад

Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.

CVSS3: 2
EPSS: Низкий
ubuntu логотип

CVE-2015-7510

почти 9 лет назад

Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2015-7509

больше 10 лет назад

fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2015-7508

больше 6 лет назад

Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the last row of RLE data in a crafted BMP file.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2015-7507

больше 6 лет назад

libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_decode_rle function.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-7506

больше 6 лет назад

The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2015-7505

больше 6 лет назад

Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-7543

aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.

CVSS3: 7
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2015-7542

A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.

CVSS3: 5.3
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2015-7540

The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.

CVSS3: 7.5
7%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7539

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

CVSS3: 7.5
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7538

Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.

CVSS3: 8.8
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7537

Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.

CVSS3: 8.8
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7536

Cross-site scripting (XSS) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to workspaces and archived artifacts.

CVSS3: 5.4
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7529

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.

CVSS3: 7.8
0%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2015-7519

agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

CVSS3: 3.7
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7515

The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device that lacks endpoints.

CVSS3: 4.6
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7514

OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.

CVSS3: 6.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-7513

arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_vm_ioctl_set_pit and kvm_vm_ioctl_set_pit2 functions.

CVSS3: 6.5
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7512

Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.

CVSS3: 9
8%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7511

Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.

CVSS3: 2
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7510

Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.

CVSS3: 9.8
4%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2015-7509

fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.

CVSS3: 4.4
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-7508

Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the last row of RLE data in a crafted BMP file.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2015-7507

libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_decode_rle function.

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2015-7506

The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF file.

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2015-7505

Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад

Уязвимостей на страницу