Show filters
228 Total Results
Displaying 141-150 of 228
Sort by:
Attacker Value
Unknown

CVE-2015-8327

Disclosure Date: December 17, 2015 (last updated October 05, 2023)
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
0
Attacker Value
Unknown

CVE-2015-7497

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-7500

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
0
Attacker Value
Unknown

CVE-2015-7499

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-7498

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
0
Attacker Value
Unknown

CVE-2015-5312

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
0
Attacker Value
Unknown

CVE-2015-8241

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
0
Attacker Value
Unknown

CVE-2015-8242

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
0
Attacker Value
Unknown

CVE-2015-8317

Disclosure Date: December 15, 2015 (last updated October 05, 2023)
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
0
Attacker Value
Unknown

CVE-2015-3276

Disclosure Date: December 07, 2015 (last updated October 05, 2023)
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.