Show filters
25 Total Results
Displaying 21-25 of 25
Sort by:
Attacker Value
Unknown

CVE-2015-7942

Disclosure Date: November 18, 2015 (last updated October 05, 2023)
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.
0
Attacker Value
Unknown

CVE-2015-1819

Disclosure Date: August 14, 2015 (last updated October 05, 2023)
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
0
Attacker Value
Unknown

CVE-2015-5523

Disclosure Date: August 11, 2015 (last updated October 05, 2023)
The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.
0
Attacker Value
Unknown

CVE-2015-5522

Disclosure Date: August 11, 2015 (last updated October 05, 2023)
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.
0
Attacker Value
Unknown

CVE-2015-4000

Disclosure Date: May 21, 2015 (last updated October 23, 2024)
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.
0