Vendor CVEs
Debian
All CVEs
10,468 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2010-4073 | 0.03 | — | 0.02 | Nov 29, 2010 | The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the (1) compat_sys_semctl, (2) compat_sys_msgctl, and (3)… | |||
| CVE-2010-2963 | 0.03 | — | 0.01 | Nov 26, 2010 | drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory locations, and… | |||
| CVE-2010-3437 | 0.03 | — | 0.02 | Oct 4, 2010 | Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and system crash) via… | |||
| CVE-2010-2959 | 0.03 | — | 0.04 | Sep 8, 2010 | Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attackers to execute arbitrary code or cause a denial of service… | |||
| CVE-2010-0307 | 0.03 | — | 0.01 | Feb 17, 2010 | The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensure that the ELF interpreter is available before a call to the SET_PERSONALITY macro, which allows local users to cause a denial of service (system crash) via a… | |||
| CVE-2008-5394 | 0.03 | — | 0.01 | Dec 9, 2008 | /bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry. | |||
| CVE-2008-4192 | 0.03 | — | 0.01 | Sep 29, 2008 | The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file. | |||
| CVE-2007-6211 | 0.03 | — | 0.01 | Dec 4, 2007 | Send ICMP Nasty Garbage (sing) on Debian GNU/Linux allows local users to append to arbitrary files and gain privileges via the -L (output log file) option. NOTE: this issue is only a vulnerability in limited environments, since sing is not installed setuid, and the… | |||
| CVE-2007-5837 | 0.03 | — | 0.06 | Nov 5, 2007 | GUI.pm in yarssr 0.2.2, when Gnome default URL handling is disabled, allows remote attackers to execute arbitrary commands via shell metacharacters in a link element in a feed. | |||
| CVE-2007-2839 | 0.03 | — | 0.01 | Jul 5, 2007 | gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors. | |||
| CVE-2006-4250 | 0.03 | — | 0.01 | Apr 10, 2007 | Buffer overflow in man and mandb (man-db) 2.4.3 and earlier allows local users to execute arbitrary code via crafted arguments to the -H flag. | |||
| CVE-2006-7098 | 0.03 | — | 0.01 | Mar 3, 2007 | The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl. | |||
| CVE-2006-6942 | 0.03 | — | 0.03 | Jan 19, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the… | |||
| CVE-2004-0996 | 0.03 | — | 0.01 | Jan 10, 2005 | main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack. | |||
| CVE-2003-0649 | 0.03 | — | 0.01 | Aug 27, 2003 | Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable. | |||
| CVE-2003-0385 | 0.03 | — | 0.01 | Jul 2, 2003 | Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option. | |||
| CVE-2003-0358 | 0.03 | — | 0.01 | Jun 9, 2003 | Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option. | |||
| CVE-2003-0262 | 0.03 | — | 0.01 | May 27, 2003 | leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting unknown vulnerabilities related to the escalated privileges, which KATAXWR is not designed to have. | |||
| CVE-2002-0875 | 0.03 | — | 0.01 | Sep 5, 2002 | Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group. | |||
| CVE-2002-0004 | 0.03 | — | 0.01 | Feb 27, 2002 | Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice. | |||
| CVE-2001-1561 | 0.03 | — | 0.01 | Dec 31, 2001 | Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -T arguments. | |||
| CVE-2001-0623 | 0.03 | — | 0.01 | Aug 2, 2001 | sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when sending notification emails, which allows local attackers to gain privileges. | |||
| CVE-2001-0279 | 0.03 | — | 0.01 | May 3, 2001 | Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges. | |||
| CVE-2001-0193 | 0.03 | — | 0.01 | May 3, 2001 | Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter. | |||
| CVE-2001-0170 | 0.03 | — | 0.01 | Mar 26, 2001 | glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files. | |||
| CVE-2001-0111 | 0.03 | — | 0.01 | Mar 12, 2001 | Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument. | |||
| CVE-2001-0112 | 0.03 | — | 0.01 | Mar 12, 2001 | Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands. | |||
| CVE-2000-0584 | 0.03 | — | 0.06 | Jul 2, 2000 | Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name. | |||
| CVE-2000-0607 | 0.03 | — | 0.01 | Jun 21, 2000 | Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings. | |||
| CVE-2000-0229 | 0.03 | — | 0.01 | Mar 22, 2000 | gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root. | |||
| CVE-2000-0107 | 0.03 | — | 0.01 | Feb 1, 2000 | Linux apcd program allows local attackers to modify arbitrary files via a symlink attack. | |||
| CVE-1999-0986 | 0.03 | — | 0.04 | Dec 8, 1999 | The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option. | |||
| CVE-1999-0769 | 0.03 | — | 0.01 | Aug 25, 1999 | Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable. | |||
| CVE-1999-0730 | 0.03 | — | 0.04 | Jun 12, 1999 | The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack. | |||
| CVE-1999-0804 | 0.03 | — | 0.06 | Jun 1, 1999 | Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths. | |||
| CVE-1999-0381 | 0.03 | — | 0.01 | Feb 26, 1999 | super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access. | |||
| CVE-1999-0405 | 0.03 | — | 0.01 | Feb 18, 1999 | A buffer overflow in lsof allows local users to obtain root privilege. | |||
| CVE-1999-0914 | 0.03 | — | 0.01 | Jan 3, 1999 | Buffer overflow in the FTP client in the Debian GNU/Linux netstd package. | |||
| CVE-1999-1390 | 0.03 | — | 0.01 | Apr 28, 1998 | suidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program on the command line. | |||
| CVE-2022-0572 | Hig | 0.02 | 7.8 | 0.27 | Feb 14, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2021-3177 | Cri | 0.02 | 9.8 | 0.23 | Jan 19, 2021 | Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This… | ||
| CVE-2020-11945 | Cri | 0.02 | 9.8 | 0.27 | Apr 23, 2020 | An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code… | ||
| CVE-2020-8597 | Cri | 0.02 | 9.8 | 0.20 | Feb 3, 2020 | eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. | ||
| CVE-2018-1000802 | Cri | 0.02 | 9.8 | 0.21 | Sep 18, 2018 | Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via… | ||
| CVE-2018-5391 | Hig | 0.02 | 7.5 | 0.32 | Sep 6, 2018 | The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in… | ||
| CVE-2015-6251 | 0.02 | — | 0.19 | Aug 24, 2015 | Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate. | |||
| CVE-2015-1283 | 0.02 | — | 0.19 | Jul 23, 2015 | Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via… | |||
| CVE-2015-2331 | 0.02 | — | 0.28 | Mar 30, 2015 | Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application… | |||
| CVE-2014-8602 | 0.02 | — | 0.25 | Dec 11, 2014 | iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals. | |||
| CVE-2014-3515 | 0.02 | — | 0.30 | Jul 9, 2014 | The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable… |
- CVE-2010-4073Nov 29, 2010risk 0.03cvss —epss 0.02
The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the (1) compat_sys_semctl, (2) compat_sys_msgctl, and (3)…
- CVE-2010-2963Nov 26, 2010risk 0.03cvss —epss 0.01
drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory locations, and…
- CVE-2010-3437Oct 4, 2010risk 0.03cvss —epss 0.02
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and system crash) via…
- CVE-2010-2959Sep 8, 2010risk 0.03cvss —epss 0.04
Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attackers to execute arbitrary code or cause a denial of service…
- CVE-2010-0307Feb 17, 2010risk 0.03cvss —epss 0.01
The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensure that the ELF interpreter is available before a call to the SET_PERSONALITY macro, which allows local users to cause a denial of service (system crash) via a…
- CVE-2008-5394Dec 9, 2008risk 0.03cvss —epss 0.01
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.
- CVE-2008-4192Sep 29, 2008risk 0.03cvss —epss 0.01
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file.
- CVE-2007-6211Dec 4, 2007risk 0.03cvss —epss 0.01
Send ICMP Nasty Garbage (sing) on Debian GNU/Linux allows local users to append to arbitrary files and gain privileges via the -L (output log file) option. NOTE: this issue is only a vulnerability in limited environments, since sing is not installed setuid, and the…
- CVE-2007-5837Nov 5, 2007risk 0.03cvss —epss 0.06
GUI.pm in yarssr 0.2.2, when Gnome default URL handling is disabled, allows remote attackers to execute arbitrary commands via shell metacharacters in a link element in a feed.
- CVE-2007-2839Jul 5, 2007risk 0.03cvss —epss 0.01
gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors.
- CVE-2006-4250Apr 10, 2007risk 0.03cvss —epss 0.01
Buffer overflow in man and mandb (man-db) 2.4.3 and earlier allows local users to execute arbitrary code via crafted arguments to the -H flag.
- CVE-2006-7098Mar 3, 2007risk 0.03cvss —epss 0.01
The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when httpd is started interactively, which allows local users to gain privileges to that tty via a CGI program that calls the TIOCSTI ioctl.
- CVE-2006-6942Jan 19, 2007risk 0.03cvss —epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b) db_create.php, (3) the…
- CVE-2004-0996Jan 10, 2005risk 0.03cvss —epss 0.01
main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.
- CVE-2003-0649Aug 27, 2003risk 0.03cvss —epss 0.01
Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
- CVE-2003-0385Jul 2, 2003risk 0.03cvss —epss 0.01
Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.
- CVE-2003-0358Jun 9, 2003risk 0.03cvss —epss 0.01
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.
- CVE-2003-0262May 27, 2003risk 0.03cvss —epss 0.01
leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting unknown vulnerabilities related to the escalated privileges, which KATAXWR is not designed to have.
- CVE-2002-0875Sep 5, 2002risk 0.03cvss —epss 0.01
Vulnerability in FAM 2.6.8, 2.6.6, and other versions allows unprivileged users to obtain the names of files whose access is restricted to the root group.
- CVE-2002-0004Feb 27, 2002risk 0.03cvss —epss 0.01
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
- CVE-2001-1561Dec 31, 2001risk 0.03cvss —epss 0.01
Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -T arguments.
- CVE-2001-0623Aug 2, 2001risk 0.03cvss —epss 0.01
sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when sending notification emails, which allows local attackers to gain privileges.
- CVE-2001-0279May 3, 2001risk 0.03cvss —epss 0.01
Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
- CVE-2001-0193May 3, 2001risk 0.03cvss —epss 0.01
Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.
- CVE-2001-0170Mar 26, 2001risk 0.03cvss —epss 0.01
glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.
- CVE-2001-0111Mar 12, 2001risk 0.03cvss —epss 0.01
Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument.
- CVE-2001-0112Mar 12, 2001risk 0.03cvss —epss 0.01
Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.
- CVE-2000-0584Jul 2, 2000risk 0.03cvss —epss 0.06
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.
- CVE-2000-0607Jun 21, 2000risk 0.03cvss —epss 0.01
Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings.
- CVE-2000-0229Mar 22, 2000risk 0.03cvss —epss 0.01
gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.
- CVE-2000-0107Feb 1, 2000risk 0.03cvss —epss 0.01
Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.
- CVE-1999-0986Dec 8, 1999risk 0.03cvss —epss 0.04
The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.
- CVE-1999-0769Aug 25, 1999risk 0.03cvss —epss 0.01
Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.
- CVE-1999-0730Jun 12, 1999risk 0.03cvss —epss 0.04
The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.
- CVE-1999-0804Jun 1, 1999risk 0.03cvss —epss 0.06
Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.
- CVE-1999-0381Feb 26, 1999risk 0.03cvss —epss 0.01
super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.
- CVE-1999-0405Feb 18, 1999risk 0.03cvss —epss 0.01
A buffer overflow in lsof allows local users to obtain root privilege.
- CVE-1999-0914Jan 3, 1999risk 0.03cvss —epss 0.01
Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.
- CVE-1999-1390Apr 28, 1998risk 0.03cvss —epss 0.01
suidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program on the command line.
- risk 0.02cvss 7.8epss 0.27
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.02cvss 9.8epss 0.23
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This…
- risk 0.02cvss 9.8epss 0.27
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code…
- risk 0.02cvss 9.8epss 0.20
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
- risk 0.02cvss 9.8epss 0.21
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via…
- risk 0.02cvss 7.5epss 0.32
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in…
- CVE-2015-6251Aug 24, 2015risk 0.02cvss —epss 0.19
Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.
- CVE-2015-1283Jul 23, 2015risk 0.02cvss —epss 0.19
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via…
- CVE-2015-2331Mar 30, 2015risk 0.02cvss —epss 0.28
Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application…
- CVE-2014-8602Dec 11, 2014risk 0.02cvss —epss 0.25
iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.
- CVE-2014-3515Jul 9, 2014risk 0.02cvss —epss 0.30
The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that triggers use of a Hashtable…
Page 163 of 210