|
212001
|
8.8 |
HIGH
Network
|
redhat libpng fedoraproject debian
|
enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_hpc_node enterprise_linux_workstation_supplementary libpng fedora debian_linux
|
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.…
|
CWE-189
Numeric Errors
|
CVE-2015-8540
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212002
|
5.5 |
MEDIUM
Local
|
libtiff debian
|
libtiff debian_linux
|
The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a packed TIFF image.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8683
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212003
|
5.5 |
MEDIUM
Local
|
libtiff
|
libtiff
|
tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via the SamplesPerPixel tag in a TIFF image.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8665
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212004
|
6.1 |
MEDIUM
Network
|
silverstripe
|
silverstripe
|
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Loca…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8606
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212005
|
8.6 |
HIGH
Network
|
citrix xen
|
xenserver xen
|
Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains …
|
CWE-200
Information Exposure
|
CVE-2015-8555
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212006
|
6.5 |
MEDIUM
Local
|
xen redhat
|
xen enterprise_linux
|
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists …
|
CWE-200
Information Exposure
|
CVE-2015-8553
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212007
|
4.4 |
MEDIUM
Local
|
xen canonical debian novell
|
xen ubuntu_linux debian_linux suse_linux_enterprise_debuginfo suse_linux_enterprise_real_time_extension
|
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messag…
|
CWE-20
Improper Input Validation
|
CVE-2015-8552
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212008
|
6.0 |
MEDIUM
Local
|
linux debian suse opensuse
|
linux_kernel debian_linux linux_enterprise_server linux_enterprise_desktop linux_enterprise_software_development_kit linux_enterprise_real_time_extension linux_enterprise_workstatio…
|
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of se…
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-8551
|
2024-11-21 11:38 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212009
|
6.1 |
MEDIUM
Local
|
huawei
|
mate_s_firmware p8_firmware
|
The Video0 driver in Huawei P8 smartphones with software GRA-UL00 before GRA-UL00C00B350, GRA-UL10 before GRA-UL10C00B350, GRA-TL00 before GRA-TL00C01B350, GRA-CL00 before GRA-CL00C92B350, and GRA-CL…
|
CWE-20
Improper Input Validation
|
CVE-2015-8682
|
2024-11-21 11:38 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212010
|
7.8 |
HIGH
Local
|
avast
|
avast_free_antivirus avast_internet_security avast_premier avast_pro_antivirus
|
Heap-based buffer overflow in the Avast virtualization driver (aswSnx.sys) in Avast Internet Security, Pro Antivirus, Premier, and Free Antivirus before 11.1.2253 allows local users to gain privilege…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8620
|
2024-11-21 11:38 |
2016-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|