|
211811
|
9.8 |
CRITICAL
Network
|
nettle_project canonical opensuse
|
nettle ubuntu_linux leap opensuse
|
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allo…
|
CWE-310
Cryptographic Issues
|
CVE-2015-8805
|
2024-11-21 11:39 |
2016-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211812
|
9.8 |
CRITICAL
Network
|
nettle_project canonical opensuse
|
nettle ubuntu_linux leap opensuse
|
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to…
|
CWE-310 CWE-254
Cryptographic Issues 7PK - Security Features
|
CVE-2015-8804
|
2024-11-21 11:39 |
2016-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211813
|
9.8 |
CRITICAL
Network
|
nettle_project canonical opensuse
|
nettle ubuntu_linux leap opensuse
|
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allo…
|
CWE-310 CWE-254
Cryptographic Issues 7PK - Security Features
|
CVE-2015-8803
|
2024-11-21 11:39 |
2016-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211814
|
6.1 |
MEDIUM
Network
|
apache
|
solr
|
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8797
|
2024-11-21 11:39 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211815
|
6.1 |
MEDIUM
Network
|
apache
|
solr
|
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a craf…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8796
|
2024-11-21 11:39 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211816
|
6.1 |
MEDIUM
Network
|
apache
|
solr
|
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled duri…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8795
|
2024-11-21 11:39 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211817
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or…
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-8787
|
2024-11-21 11:39 |
2016-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211818
|
6.2 |
MEDIUM
Local
|
linux suse
|
linux_kernel linux_enterprise_real_time_extension
|
The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero lengt…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2015-8785
|
2024-11-21 11:39 |
2016-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211819
|
6.2 |
MEDIUM
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a c…
|
CWE-362
Race Condition
|
CVE-2015-8767
|
2024-11-21 11:39 |
2016-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211820
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter th…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8709
|
2024-11-21 11:39 |
2016-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|