|
212071
|
5.5 |
MEDIUM
Local
|
libtiff
|
libtiff
|
tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via the SamplesPerPixel tag in a TIFF image.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8665
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212072
|
6.1 |
MEDIUM
Network
|
silverstripe
|
silverstripe
|
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Loca…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8606
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212073
|
8.6 |
HIGH
Network
|
citrix xen
|
xenserver xen
|
Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains …
|
CWE-200
Information Exposure
|
CVE-2015-8555
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212074
|
6.5 |
MEDIUM
Local
|
xen redhat
|
xen enterprise_linux
|
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists …
|
CWE-200
Information Exposure
|
CVE-2015-8553
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212075
|
4.4 |
MEDIUM
Local
|
xen canonical debian novell
|
xen ubuntu_linux debian_linux suse_linux_enterprise_debuginfo suse_linux_enterprise_real_time_extension
|
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messag…
|
CWE-20
Improper Input Validation
|
CVE-2015-8552
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212076
|
6.0 |
MEDIUM
Local
|
linux debian suse opensuse
|
linux_kernel debian_linux linux_enterprise_server linux_enterprise_desktop linux_enterprise_software_development_kit linux_enterprise_real_time_extension linux_enterprise_workstatio…
|
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of se…
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-8551
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212077
|
6.1 |
MEDIUM
Local
|
huawei
|
mate_s_firmware p8_firmware
|
The Video0 driver in Huawei P8 smartphones with software GRA-UL00 before GRA-UL00C00B350, GRA-UL10 before GRA-UL10C00B350, GRA-TL00 before GRA-TL00C01B350, GRA-CL00 before GRA-CL00C92B350, and GRA-CL…
|
CWE-20
Improper Input Validation
|
CVE-2015-8682
|
2024-11-21 11:38 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212078
|
7.8 |
HIGH
Local
|
avast
|
avast_free_antivirus avast_internet_security avast_premier avast_pro_antivirus
|
Heap-based buffer overflow in the Avast virtualization driver (aswSnx.sys) in Avast Internet Security, Pro Antivirus, Premier, and Free Antivirus before 11.1.2253 allows local users to gain privilege…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8620
|
2024-11-21 11:38 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212079
|
7.8 |
HIGH
Local
|
huawei
|
p7_firmware
|
Integer overflow in Huawei P7 phones with software before P7-L07 V100R001C01B606 allows remote attackers to gain privileges via a crafted application with the system or camera permission.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8304
|
2024-11-21 11:38 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212080
|
8.6 |
HIGH
Network
|
debian inspircd
|
debian_linux inspircd
|
The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\0…
|
CWE-20
Improper Input Validation
|
CVE-2015-8702
|
2024-11-21 11:38 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|