|
211941
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
Double free vulnerability in epan/dissectors/packet-nlm.c in the NLM dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1, when the "Match MSG/RES packets for async NLM" option is enabl…
|
CWE-20
Improper Input Validation
|
CVE-2015-8718
|
2024-11-21 11:39 |
2016-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211942
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
The dissect_sdp function in epan/dissectors/packet-sdp.c in the SDP dissector in Wireshark 1.12.x before 1.12.9 does not prevent use of a negative media count, which allows remote attackers to cause …
|
CWE-20
Improper Input Validation
|
CVE-2015-8717
|
2024-11-21 11:39 |
2016-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211943
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
The init_t38_info_conv function in epan/dissectors/packet-t38.c in the T.38 dissector in Wireshark 1.12.x before 1.12.9 does not ensure that a conversation exists, which allows remote attackers to ca…
|
CWE-20
Improper Input Validation
|
CVE-2015-8716
|
2024-11-21 11:39 |
2016-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211944
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
epan/dissectors/packet-alljoyn.c in the AllJoyn dissector in Wireshark 1.12.x before 1.12.9 does not check for empty arguments, which allows remote attackers to cause a denial of service (infinite lo…
|
CWE-20
Improper Input Validation
|
CVE-2015-8715
|
2024-11-21 11:39 |
2016-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211945
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
The dissect_dcom_OBJREF function in epan/dissectors/packet-dcom.c in the DCOM dissector in Wireshark 1.12.x before 1.12.9 does not initialize a certain IPv4 data structure, which allows remote attack…
|
CWE-20
Improper Input Validation
|
CVE-2015-8714
|
2024-11-21 11:39 |
2016-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211946
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not properly reserve memory for channel ID mappings, which allows remote attackers to cause a denial o…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2015-8713
|
2024-11-21 11:39 |
2016-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211947
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
The dissect_hsdsch_channel_info function in epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not validate the number of PDUs, which allows remote attac…
|
CWE-20
Improper Input Validation
|
CVE-2015-8712
|
2024-11-21 11:39 |
2016-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211948
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate conversation data, which allows remote attackers to cause a denial of se…
|
CWE-20
Improper Input Validation
|
CVE-2015-8711
|
2024-11-21 11:39 |
2016-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211949
|
7.5 |
HIGH
Network
|
heartcombo
|
devise
|
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2015-8314
|
2024-11-21 11:38 |
2023-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211950
|
8.8 |
HIGH
Network
|
getcomposer
|
composer
|
Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because o…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2015-8371
|
2024-11-21 11:38 |
2023-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|