|
1321
|
-
4.9
|
MEDIUM
|
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges …
|
NVD-CWE-Other
|
CVE-2015-3636
|
cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:29
2015-08-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1322
|
-
4.0
|
MEDIUM
|
Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability …
|
NVD-CWE-noinfo
|
CVE-2015-4756
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:31
2015-07-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1323
|
-
4.3
|
MEDIUM
|
Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 an…
|
CWE-189 CWE-362
Numeric Errors Race Condition
|
CVE-2015-3216
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 11:28
2015-07-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1324
|
-
5.0
|
MEDIUM
|
RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests t…
|
CWE-254
7PK - Security Features
|
CVE-2015-3900
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:30
2015-06-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1325
|
-
7.5
|
HIGH
|
The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass i…
|
CWE-19
Data Processing Errors
|
CVE-2015-4026
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:30
2015-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1326
|
-
7.5
|
HIGH
|
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extensio…
|
CWE-19
Data Processing Errors
|
CVE-2015-4025
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:30
2015-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1327
|
-
5.0
|
MEDIUM
|
Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a de…
|
CWE-399
Resource Management Errors
|
CVE-2015-4024
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:30
2015-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1328
|
-
7.5
|
HIGH
|
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to…
|
CWE-189
Numeric Errors
|
CVE-2015-4022
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:30
2015-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1329
|
-
5.0
|
MEDIUM
|
The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first character of a filename is different from the \0 cha…
|
CWE-189
Numeric Errors
|
CVE-2015-4021
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:30
2015-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1330
|
-
6.8
|
MEDIUM
|
The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to…
|
CWE-20
Improper Input Validation
|
CVE-2015-3330
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:29
2015-06-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|