Latest CVE Feed
-
5.0
MEDIUMCVE-2015-7998
The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allo... Read more
- EPSS Score: %0.29
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7997
Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service D... Read more
- EPSS Score: %0.29
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-7996
The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow attack... Read more
- EPSS Score: %0.29
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-7995
The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.... Read more
- EPSS Score: %3.04
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-7812
The hypercall_create_continuation function in arch/arm/domain.c in Xen 4.4.x through 4.6.x allows local guest users to cause a denial of service (host crash) via a preemptible hypercall to the multicall interface.... Read more
Affected Products : xen- EPSS Score: %0.08
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-7805
Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file.... Read more
- EPSS Score: %51.99
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-5602
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcards in /etc/sudoers, as demonstrated by "/home/*/*/file.txt."... Read more
- EPSS Score: %6.10
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5311
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.... Read more
- EPSS Score: %85.30
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-5301
providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.2 and 1.1.x before 1.1.1 does not properly check permissions, which allows remote authenticated users to cause a denial of service by deleting a SAML2 Service Provi... Read more
Affected Products : ipsilon- EPSS Score: %0.72
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5276
The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-dependent attackers to predict the random values via unspecified ... Read more
Affected Products : gcc- EPSS Score: %0.45
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-5217
providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly check permissions to update the SAML2 Service Provider (SP) owner, which allows remote authenticated users to cause a denial of service via a du... Read more
Affected Products : ipsilon- EPSS Score: %0.39
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0272
GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215.... Read more
- EPSS Score: %0.91
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8219
The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-value constraints on tile coordinates, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly... Read more
Affected Products : ffmpeg- EPSS Score: %0.46
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-8218
The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via cra... Read more
Affected Products : ffmpeg- EPSS Score: %0.43
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8217
The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indicator, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact ... Read more
Affected Products : ffmpeg- EPSS Score: %0.52
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8216
The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8.2 omits certain width and height checks, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via... Read more
Affected Products : ffmpeg- EPSS Score: %0.52
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-8215
net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0 does not validate attempted changes to the MTU value, which allows context-dependent attackers to cause a denial of service (packet loss) via a value that is (1) smaller than the minimum... Read more
Affected Products : linux_kernel- EPSS Score: %6.24
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
3.3
LOWCVE-2015-2924
The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisemen... Read more
- EPSS Score: %0.59
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-7897
The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges or cause a denial of service (memory corruption) via a crafted BMP image fi... Read more
Affected Products : galaxy_s6- EPSS Score: %4.51
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-7816
The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection attacks, conduct Server-Side Request Forgery (SSRF) attacks, and execute arbitrary PHP code via a crafted HT... Read more
Affected Products : matomo- EPSS Score: %0.42
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025