Latest CVE Feed
-
6.8
MEDIUMCVE-2015-8218
The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via cra... Read more
Affected Products : ffmpeg- EPSS Score: %0.43
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8217
The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indicator, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact ... Read more
Affected Products : ffmpeg- EPSS Score: %0.52
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8216
The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8.2 omits certain width and height checks, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via... Read more
Affected Products : ffmpeg- EPSS Score: %0.52
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-8215
net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0 does not validate attempted changes to the MTU value, which allows context-dependent attackers to cause a denial of service (packet loss) via a value that is (1) smaller than the minimum... Read more
Affected Products : linux_kernel- EPSS Score: %6.24
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
3.3
LOWCVE-2015-2924
The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisemen... Read more
- EPSS Score: %0.59
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-7897
The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges or cause a denial of service (memory corruption) via a crafted BMP image fi... Read more
Affected Products : galaxy_s6- EPSS Score: %4.51
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-7816
The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection attacks, conduct Server-Side Request Forgery (SSRF) attacks, and execute arbitrary PHP code via a crafted HT... Read more
Affected Products : matomo- EPSS Score: %0.42
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-7815
Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute arbitrary local files via the viewDataTable parameter.... Read more
Affected Products : matomo- EPSS Score: %1.35
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-7712
Multiple eval injection vulnerabilities in mods/_standard/gradebook/edit_marks.php in ATutor 2.2 and earlier allow remote authenticated users with the AT_PRIV_GRADEBOOK privilege to execute arbitrary PHP code via the (1) asc or (2) desc parameter.... Read more
Affected Products : atutor- EPSS Score: %0.60
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2014-9752
Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension as a customicon for a new course, then... Read more
Affected Products : atutor- EPSS Score: %0.70
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
10.0
CRITICALCVE-2015-8104
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c.... Read more
- EPSS Score: %0.35
- Published: Nov. 16, 2015
- Modified: Apr. 23, 2025
-
2.1
LOWCVE-2015-7872
The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
4.4
MEDIUMCVE-2015-7312
Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.patch patches for the Linux kernel 3.x and 4.x allow local users to cause a denial of service (use-after-free and BUG) or possibly gain privileges via a (1) m... Read more
- EPSS Score: %0.04
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-5307
The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.... Read more
- EPSS Score: %0.17
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-5257
drivers/usb/serial/whiteheat.c in the Linux kernel before 4.2.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted USB device. NOTE: this ID was i... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-2925
The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a "dou... Read more
- EPSS Score: %0.96
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7830
The pcapng_read_if_descr_block function in wiretap/pcapng.c in the pcapng parser in Wireshark 1.12.x before 1.12.8 uses too many levels of pointer indirection, which allows remote attackers to cause a denial of service (incorrect free and application cras... Read more
- EPSS Score: %0.57
- Published: Nov. 15, 2015
- Modified: Apr. 12, 2025
-
7.7
HIGHCVE-2015-3977
Buffer overflow in Schneider Electric IMT25 Magnetic Flow DTM before 1.500.004 for the HART Protocol allows remote authenticated users to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HART reply.... Read more
Affected Products : imt25_magnetic_flow_dtm- EPSS Score: %0.13
- Published: Nov. 15, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-7774
PC-EGG pWebManager before 3.3.10, and before 2.2.2 for PHP 4.x, allows remote authenticated users to execute arbitrary OS commands by leveraging the editor role.... Read more
- EPSS Score: %0.50
- Published: Nov. 14, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-7427
IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x before 7.2.0.1 do not set the secure flag for unspecified cookies in an https session, which makes it easie... Read more
Affected Products : datapower_gateway- EPSS Score: %0.22
- Published: Nov. 14, 2015
- Modified: Apr. 12, 2025