Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 969

Количество 77 969

ubuntu логотип

CVE-2015-0885

больше 11 лет назад

checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-0881

больше 11 лет назад

CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-0862

больше 11 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) message details when a message is unqueued, such as headers or arguments; (2) policy names, which are not properly handled when viewing policies; (3) details for AMQP network clients, such as the version; allow remote authenticated administrators to inject arbitrary web script or HTML via (4) user names, (5) the cluster name; or allow RabbitMQ cluster administrators to (6) modify unspecified content.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2015-0861

больше 10 лет назад

model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-0860

почти 11 лет назад

Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an "old-style" Debian binary package, which triggers a stack-based buffer overflow.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-0859

почти 11 лет назад

The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes arguments to smokeping_cgi, which allows remote attackers to execute arbitrary code via crafted CGI arguments.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-0858

больше 10 лет назад

Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory.

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2015-0857

больше 10 лет назад

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2015-0856

почти 11 лет назад

daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2015-0855

больше 9 лет назад

The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file path.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2015-0854

больше 9 лет назад

App/HelperFunctions.pm in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Show in Folder" action.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2015-0853

около 9 лет назад

svn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by using the "Command Shell" menu item while in the directory trunk/$(xeyes).

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2015-0852

почти 11 лет назад

Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-0851

около 11 лет назад

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-0850

больше 11 лет назад

The Git plugin for FusionForge before 6.0rc4 allows remote attackers to execute arbitrary code via an unspecified parameter when creating a secondary Git repository.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2015-0849

около 1 года назад

pycode-browser before version 1.0 is prone to a predictable temporary file vulnerability.

CVSS3: 3.9
EPSS: Низкий
ubuntu логотип

CVE-2015-0848

около 11 лет назад

Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2015-0847

больше 11 лет назад

nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of service (deadlock) via unspecified vectors.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2015-0846

больше 11 лет назад

django-markupfield before 1.3.2 uses the default docutils RESTRUCTUREDTEXT_FILTER_SETTINGS settings, which allows remote attackers to include and read arbitrary files via unspecified vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-0845

больше 11 лет назад

Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-0885

checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.

CVSS2: 5
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-0881

CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.

CVSS2: 4.3
5%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-0862

Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) message details when a message is unqueued, such as headers or arguments; (2) policy names, which are not properly handled when viewing policies; (3) details for AMQP network clients, such as the version; allow remote authenticated administrators to inject arbitrary web script or HTML via (4) user names, (5) the cluster name; or allow RabbitMQ cluster administrators to (6) modify unspecified content.

CVSS2: 3.5
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-0861

model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.

CVSS3: 4.3
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-0860

Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an "old-style" Debian binary package, which triggers a stack-based buffer overflow.

CVSS2: 7.5
5%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-0859

The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes arguments to smokeping_cgi, which allows remote attackers to execute arbitrary code via crafted CGI arguments.

CVSS2: 7.5
2%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-0858

Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory.

CVSS3: 3.3
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-0857

Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.

CVSS3: 9.8
5%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2015-0856

daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.

CVSS2: 4.6
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-0855

The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file path.

CVSS3: 9.8
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-0854

App/HelperFunctions.pm in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Show in Folder" action.

CVSS3: 7.8
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2015-0853

svn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by using the "Command Shell" menu item while in the directory trunk/$(xeyes).

CVSS3: 8.8
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2015-0852

Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.

CVSS2: 5
3%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-0851

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

CVSS2: 5
2%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-0850

The Git plugin for FusionForge before 6.0rc4 allows remote attackers to execute arbitrary code via an unspecified parameter when creating a secondary Git repository.

CVSS2: 10
4%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-0849

pycode-browser before version 1.0 is prone to a predictable temporary file vulnerability.

CVSS3: 3.9
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2015-0848

Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.

CVSS2: 6.8
9%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-0847

nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of service (deadlock) via unspecified vectors.

CVSS2: 7.8
3%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-0846

django-markupfield before 1.3.2 uses the default docutils RESTRUCTUREDTEXT_FILTER_SETTINGS settings, which allows remote attackers to include and read arbitrary files via unspecified vectors.

CVSS2: 5
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-0845

Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates.

CVSS2: 7.5
4%
Низкий
больше 11 лет назад

Уязвимостей на страницу