Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 969

Количество 77 969

ubuntu логотип

CVE-2015-1592

больше 11 лет назад

Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attackers to include and execute arbitrary local Perl files and possibly execute arbitrary code via unspecified vectors.

CVSS2: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2015-1591

около 9 лет назад

The kamailio build in kamailio before 4.2.0-2 process allows local users to gain privileges.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2015-1590

около 9 лет назад

The kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2015-1589

больше 11 лет назад

Directory traversal vulnerability in arCHMage 0.2.4 allows remote attackers to write to arbitrary files via a .. (dot dot) in a CHM file.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-1573

больше 10 лет назад

The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2015-1572

больше 11 лет назад

Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2015-1564

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in style-underground/search in Plain Black WebGUI 7.10.29 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-1563

больше 11 лет назад

The ARM GIC distributor virtualization in Xen 4.4.x and 4.5.x allows local guests to cause a denial of service by causing a large number messages to be logged.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2015-1558

больше 11 лет назад

Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2015-1555

около 9 лет назад

Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using session validators.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2015-1554

около 9 лет назад

kgb-bot 1.33-2 allows remote attackers to cause a denial of service (crash).

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-1547

больше 10 лет назад

The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff5.tif.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2015-1546

больше 11 лет назад

Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-1545

больше 11 лет назад

The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2015-1541

почти 11 лет назад

The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application that sends an Intent with a (1) FLAG_GRANT_READ_URI_PERMISSION or (2) FLAG_GRANT_WRITE_URI_PERMISSION flag, as demonstrated by bypassing intended restrictions on reading contacts, aka internal bug 19618745.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-1539

почти 11 лет назад

Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via crafted ESDS atoms, aka internal bug 20139950, a related issue to CVE-2015-4493.

CVSS2: 10
EPSS: Высокий
ubuntu логотип

CVE-2015-1538

почти 11 лет назад

Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496.

CVSS2: 10
EPSS: Критический
ubuntu логотип

CVE-2015-1536

почти 11 лет назад

Integer overflow in the Bitmap_createFromParcel function in core/jni/android/graphics/Bitmap.cpp in Android before 5.1.1 LMY48I allows attackers to cause a denial of service (system_server crash) or obtain sensitive system_server memory-content information via a crafted application that leverages improper unmarshalling of bitmaps, aka internal bug 19666945.

CVSS2: 8.5
EPSS: Низкий
ubuntu логотип

CVE-2015-1528

почти 11 лет назад

Integer overflow in the native_handle_create function in libcutils/native_handle.c in Android before 5.1.1 LMY48M allows attackers to obtain a different application's privileges or cause a denial of service (Binder heap memory corruption) via a crafted application, aka internal bug 19334482.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2015-1526

почти 9 лет назад

The media_server component in Android allows remote attackers to cause a denial of service via a crafted application.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-1592

Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attackers to include and execute arbitrary local Perl files and possibly execute arbitrary code via unspecified vectors.

CVSS2: 7.5
75%
Высокий
больше 11 лет назад
ubuntu логотип
CVE-2015-1591

The kamailio build in kamailio before 4.2.0-2 process allows local users to gain privileges.

CVSS3: 7.8
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2015-1590

The kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl.

CVSS3: 7.8
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2015-1589

Directory traversal vulnerability in arCHMage 0.2.4 allows remote attackers to write to arbitrary files via a .. (dot dot) in a CHM file.

CVSS2: 5
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-1573

The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability.

CVSS3: 5.5
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-1572

Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.

CVSS2: 4.6
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-1564

Cross-site scripting (XSS) vulnerability in style-underground/search in Plain Black WebGUI 7.10.29 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-1563

The ARM GIC distributor virtualization in Xen 4.4.x and 4.5.x allows local guests to cause a denial of service by causing a large number messages to be logged.

CVSS2: 2.1
0%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-1558

Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.

CVSS2: 3.5
3%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-1555

Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using session validators.

CVSS3: 9.1
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2015-1554

kgb-bot 1.33-2 allows remote attackers to cause a denial of service (crash).

CVSS3: 7.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2015-1547

The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff5.tif.

CVSS3: 6.5
3%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-1546

Double free vulnerability in the get_vrFilter function in servers/slapd/filter.c in OpenLDAP 2.4.40 allows remote attackers to cause a denial of service (crash) via a crafted search query with a matched values control.

CVSS2: 5
3%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-1545

The deref_parseCtrl function in servers/slapd/overlays/deref.c in OpenLDAP 2.4.13 through 2.4.40 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an empty attribute list in a deref control in a search request.

CVSS2: 5
11%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2015-1541

The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application that sends an Intent with a (1) FLAG_GRANT_READ_URI_PERMISSION or (2) FLAG_GRANT_WRITE_URI_PERMISSION flag, as demonstrated by bypassing intended restrictions on reading contacts, aka internal bug 19618745.

CVSS2: 4.3
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-1539

Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via crafted ESDS atoms, aka internal bug 20139950, a related issue to CVE-2015-4493.

CVSS2: 10
86%
Высокий
почти 11 лет назад
ubuntu логотип
CVE-2015-1538

Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote attackers to execute arbitrary code via crafted atoms in MP4 data that trigger an unchecked multiplication, aka internal bug 20139950, a related issue to CVE-2015-4496.

CVSS2: 10
99%
Критический
почти 11 лет назад
ubuntu логотип
CVE-2015-1536

Integer overflow in the Bitmap_createFromParcel function in core/jni/android/graphics/Bitmap.cpp in Android before 5.1.1 LMY48I allows attackers to cause a denial of service (system_server crash) or obtain sensitive system_server memory-content information via a crafted application that leverages improper unmarshalling of bitmaps, aka internal bug 19666945.

CVSS2: 8.5
1%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-1528

Integer overflow in the native_handle_create function in libcutils/native_handle.c in Android before 5.1.1 LMY48M allows attackers to obtain a different application's privileges or cause a denial of service (Binder heap memory corruption) via a crafted application, aka internal bug 19334482.

CVSS2: 9.3
3%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-1526

The media_server component in Android allows remote attackers to cause a denial of service via a crafted application.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад

Уязвимостей на страницу