Show filters
282 Total Results
Displaying 21-30 of 282
Sort by:
Attacker Value
Unknown
CVE-2015-8126
Disclosure Date: November 13, 2015 (last updated October 05, 2023)
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.
0
Attacker Value
Unknown
CVE-2015-2697
Disclosure Date: November 09, 2015 (last updated October 05, 2023)
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
0
Attacker Value
Unknown
CVE-2015-2695
Disclosure Date: November 09, 2015 (last updated October 05, 2023)
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
0
Attacker Value
Unknown
CVE-2015-1283
Disclosure Date: July 23, 2015 (last updated October 05, 2023)
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
0
Attacker Value
Unknown
CVE-2015-2568
Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileges.
0
Attacker Value
Unknown
CVE-2015-0433
Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
0
Attacker Value
Unknown
CVE-2015-0829
Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
0
Attacker Value
Unknown
CVE-2015-0828
Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Double free vulnerability in the nsXMLHttpRequest::GetResponse function in Mozilla Firefox before 36.0, when a nonstandard memory allocator is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted JavaScript code that makes an XMLHttpRequest call with zero bytes of data.
0
Attacker Value
Unknown
CVE-2015-0411
Disclosure Date: January 21, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security : Encryption.
0
Attacker Value
Unknown
CVE-2015-1038
Disclosure Date: January 21, 2015 (last updated October 05, 2023)
p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
0