Show filters
91 Total Results
Displaying 31-40 of 91
Sort by:
Attacker Value
Unknown

CVE-2015-3814

Disclosure Date: May 26, 2015 (last updated October 05, 2023)
The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 interpret a zero value as a length rather than an error condition, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
0
Attacker Value
Unknown

CVE-2015-3988

Disclosure Date: May 19, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate.
0
Attacker Value
Unknown

CVE-2015-3455

Disclosure Date: May 18, 2015 (last updated October 05, 2023)
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.
0
Attacker Value
Unknown

CVE-2015-3646

Disclosure Date: May 12, 2015 (last updated October 05, 2023)
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.
0
Attacker Value
Unknown

CVE-2015-3294

Disclosure Date: May 08, 2015 (last updated October 05, 2023)
The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and crash) via a malformed DNS request.
0
Attacker Value
Unknown

CVE-2015-2578

Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows remote attackers to affect availability via vectors related to Kernel IDMap.
0
Attacker Value
Unknown

CVE-2015-0448

Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via vectors related to ZFS File system.
0
Attacker Value
Unknown

CVE-2015-0471

Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle Sun Solaris 10 and 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to libelfsign.
0
Attacker Value
Unknown

CVE-2015-1351

Disclosure Date: March 30, 2015 (last updated October 05, 2023)
Use-after-free vulnerability in the _zend_shared_memdup function in zend_shared_alloc.c in the OPcache extension in PHP through 5.6.7 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2015-2317

Disclosure Date: March 25, 2015 (last updated October 05, 2023)
The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.
0