Show filters
270 Total Results
Displaying 71-80 of 270
Sort by:
Attacker Value
Unknown
CVE-2016-2381
Disclosure Date: April 08, 2016 (last updated November 25, 2024)
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
0
Attacker Value
Unknown
CVE-2016-1285
Disclosure Date: March 09, 2016 (last updated December 01, 2023)
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
0
Attacker Value
Unknown
CVE-2016-1286
Disclosure Date: March 09, 2016 (last updated December 01, 2023)
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
0
Attacker Value
Unknown
CVE-2015-4112
Disclosure Date: November 19, 2015 (last updated October 05, 2023)
The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site, related to a "cross frame scripting" issue.
0
Attacker Value
Unknown
CVE-2015-3237
Disclosure Date: June 22, 2015 (last updated October 05, 2023)
The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.
0
Attacker Value
Unknown
CVE-2015-2568
Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileges.
0
Attacker Value
Unknown
CVE-2015-0500
Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors.
0
Attacker Value
Unknown
CVE-2015-0433
Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
0
Attacker Value
Unknown
CVE-2015-0423
Disclosure Date: April 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
0
Attacker Value
Unknown
CVE-2015-2808
Disclosure Date: April 01, 2015 (last updated October 05, 2023)
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
0