Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 969

Количество 77 969

ubuntu логотип

CVE-2015-4732

около 11 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-2590.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2015-4731

около 11 лет назад

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; Java SE Embedded 7u75; and Java SE Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2015-4730

почти 11 лет назад

Unspecified vulnerability in Oracle MySQL 5.6.20 and earlier allows remote authenticated users to affect availability via unknown vectors related to Types.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2015-4729

около 11 лет назад

Unspecified vulnerability in Oracle Java SE 7u80 and 8u45 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Deployment.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2015-4718

почти 11 лет назад

The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via a ; (semicolon) character in a file.

CVSS2: 9
EPSS: Низкий
ubuntu логотип

CVE-2015-4717

почти 11 лет назад

The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2015-4716

почти 11 лет назад

Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the application or execute arbitrary code via unspecified vectors.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2015-4715

больше 6 лет назад

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2015-4707

почти 9 лет назад

Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/notebooks path.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2015-4706

почти 9 лет назад

Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/contents path.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2015-4700

около 11 лет назад

The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux kernel before 4.0.6 allows local users to cause a denial of service (system crash) by creating a packet filter and then loading crafted BPF instructions that trigger late convergence by the JIT compiler.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2015-4696

около 11 лет назад

Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-4695

около 11 лет назад

meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-4692

около 11 лет назад

The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2015-4680

больше 9 лет назад

FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-4663

больше 10 лет назад

EPSS: Низкий
ubuntu логотип

CVE-2015-4652

около 11 лет назад

epan/dissectors/packet-gsm_a_dtap.c in the GSM DTAP dissector in Wireshark 1.12.x before 1.12.6 does not properly validate digit characters, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the de_emerg_num_list and de_bcd_num functions.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-4651

около 11 лет назад

The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-4646

больше 9 лет назад

(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-4645

больше 9 лет назад

Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-4732

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-2590.

CVSS2: 10
6%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-4731

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; Java SE Embedded 7u75; and Java SE Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

CVSS2: 10
6%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-4730

Unspecified vulnerability in Oracle MySQL 5.6.20 and earlier allows remote authenticated users to affect availability via unknown vectors related to Types.

CVSS2: 4
2%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-4729

Unspecified vulnerability in Oracle Java SE 7u80 and 8u45 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Deployment.

CVSS2: 4
3%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-4718

The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via a ; (semicolon) character in a file.

CVSS2: 9
3%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-4717

The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names.

CVSS2: 7.8
3%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-4716

Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the application or execute arbitrary code via unspecified vectors.

CVSS2: 10
25%
Средний
почти 11 лет назад
ubuntu логотип
CVE-2015-4715

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

CVSS3: 4.9
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2015-4707

Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/notebooks path.

CVSS3: 6.1
2%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2015-4706

Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/contents path.

CVSS3: 6.1
2%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2015-4700

The bpf_int_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux kernel before 4.0.6 allows local users to cause a denial of service (system crash) by creating a packet filter and then loading crafted BPF instructions that trigger late convergence by the JIT compiler.

CVSS2: 4.9
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-4696

Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.

CVSS2: 4.3
6%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-4695

meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.

CVSS2: 5
7%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-4692

The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call.

CVSS2: 4.9
0%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-4680

FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.

CVSS3: 7.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
больше 10 лет назад
ubuntu логотип
CVE-2015-4652

epan/dissectors/packet-gsm_a_dtap.c in the GSM DTAP dissector in Wireshark 1.12.x before 1.12.6 does not properly validate digit characters, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the de_emerg_num_list and de_bcd_num functions.

CVSS2: 4.3
2%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-4651

The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS2: 5
4%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-4646

(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.

CVSS3: 7.5
7%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-4645

Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.

CVSS3: 5.5
3%
Низкий
больше 9 лет назад

Уязвимостей на страницу