Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2015-5276

    The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-dependent attackers to predict the random values via unspecified ... Read more

    Affected Products : gcc
    • EPSS Score: %0.45
    • Published: Nov. 17, 2015
    • Modified: Apr. 12, 2025
  • 4.0

    MEDIUM
    CVE-2015-5217

    providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly check permissions to update the SAML2 Service Provider (SP) owner, which allows remote authenticated users to cause a denial of service via a du... Read more

    Affected Products : ipsilon
    • EPSS Score: %0.39
    • Published: Nov. 17, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-0272

    GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215.... Read more

    • EPSS Score: %0.91
    • Published: Nov. 17, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-8219

    The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-value constraints on tile coordinates, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly... Read more

    Affected Products : ffmpeg
    • EPSS Score: %0.46
    • Published: Nov. 17, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-8218

    The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via cra... Read more

    Affected Products : ffmpeg
    • EPSS Score: %0.43
    • Published: Nov. 17, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-8217

    The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indicator, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact ... Read more

    Affected Products : ffmpeg
    • EPSS Score: %0.52
    • Published: Nov. 17, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-8216

    The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8.2 omits certain width and height checks, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via... Read more

    Affected Products : ffmpeg
    • EPSS Score: %0.52
    • Published: Nov. 17, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-8215

    net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0 does not validate attempted changes to the MTU value, which allows context-dependent attackers to cause a denial of service (packet loss) via a value that is (1) smaller than the minimum... Read more

    Affected Products : linux_kernel
    • EPSS Score: %6.24
    • Published: Nov. 16, 2015
    • Modified: Apr. 12, 2025
  • 3.3

    LOW
    CVE-2015-2924

    The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisemen... Read more

    Affected Products : networkmanager networkmanager
    • EPSS Score: %0.59
    • Published: Nov. 16, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-7897

    The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges or cause a denial of service (memory corruption) via a crafted BMP image fi... Read more

    Affected Products : galaxy_s6
    • EPSS Score: %4.51
    • Published: Nov. 16, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-7816

    The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection attacks, conduct Server-Side Request Forgery (SSRF) attacks, and execute arbitrary PHP code via a crafted HT... Read more

    Affected Products : matomo
    • EPSS Score: %0.42
    • Published: Nov. 16, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-7815

    Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute arbitrary local files via the viewDataTable parameter.... Read more

    Affected Products : matomo
    • EPSS Score: %1.35
    • Published: Nov. 16, 2015
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2015-7712

    Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated users with the AT_PRIV_GRADEBOOK privilege to execute arbitrary PHP code via the (1) asc or (2) desc parameter.... Read more

    Affected Products : atutor
    • EPSS Score: %0.60
    • Published: Nov. 16, 2015
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2014-9752

    Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension as a customicon for a new course, then... Read more

    Affected Products : atutor
    • EPSS Score: %0.70
    • Published: Nov. 16, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    CRITICAL
    CVE-2015-8104

    The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.... Read more

    • EPSS Score: %0.35
    • Published: Nov. 16, 2015
    • Modified: Apr. 23, 2025
  • 2.1

    LOW
    CVE-2015-7872

    The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.... Read more

    Affected Products : linux_kernel
    • EPSS Score: %0.06
    • Published: Nov. 16, 2015
    • Modified: Apr. 12, 2025
  • 4.4

    MEDIUM
    CVE-2015-7312

    Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.patch patches for the Linux kernel 3.x and 4.x allow local users to cause a denial of service (use-after-free and BUG) or possibly gain privileges via a (1) m... Read more

    Affected Products : linux_kernel ubuntu_linux debian_linux
    • EPSS Score: %0.04
    • Published: Nov. 16, 2015
    • Modified: Apr. 12, 2025
  • 4.9

    MEDIUM
    CVE-2015-5307

    The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.... Read more

    • EPSS Score: %0.17
    • Published: Nov. 16, 2015
    • Modified: Apr. 12, 2025
  • 4.9

    MEDIUM
    CVE-2015-5257

    drivers/usb/serial/whiteheat.c in the Linux kernel before 4.2.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted USB device. NOTE: this ID was i... Read more

    Affected Products : linux_kernel
    • EPSS Score: %0.08
    • Published: Nov. 16, 2015
    • Modified: Apr. 12, 2025
  • 6.9

    MEDIUM
    CVE-2015-2925

    The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a "dou... Read more

    Affected Products : linux_kernel ubuntu_linux debian_linux
    • EPSS Score: %0.96
    • Published: Nov. 16, 2015
    • Modified: Apr. 12, 2025
Showing 20 of 291295 Results