|
212061
|
7.5 |
HIGH
Network
|
mit
|
kerberos_5
|
The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.4 and 1.14.x before 1.…
|
NVD-CWE-Other
|
CVE-2015-8630
|
2024-11-21 11:38 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212062
|
6.5 |
MEDIUM
Network
|
mit opensuse debian redhat oracle
|
kerberos_5 leap opensuse debian_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server …
|
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (mem…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2015-8631
|
2024-11-21 11:38 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212063
|
5.3 |
MEDIUM
Network
|
mit oracle debian opensuse redhat
|
kerberos_5 solaris linux debian_linux leap opensuse enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterpr…
|
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which…
|
CWE-125
Out-of-bounds Read
|
CVE-2015-8629
|
2024-11-21 11:38 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212064
|
9.1 |
CRITICAL
Network
|
atlassian
|
bamboo
|
Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, …
|
CWE-284
Improper Access Control
|
CVE-2015-8361
|
2024-11-21 11:38 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212065
|
9.8 |
CRITICAL
Network
|
atlassian
|
bamboo
|
An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port.
|
CWE-20
Improper Input Validation
|
CVE-2015-8360
|
2024-11-21 11:38 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212066
|
4.0 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and b…
|
CWE-200
Information Exposure
|
CVE-2015-8575
|
2024-11-21 11:38 |
2016-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212067
|
7.8 |
HIGH
Local
|
suse canonical linux
|
linux_enterprise_real_time_extension ubuntu_linux linux_kernel
|
The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to se…
|
CWE-269
Improper Privilege Management
|
CVE-2015-8539
|
2024-11-21 11:38 |
2016-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212068
|
7.5 |
HIGH
Network
|
fisher-price
|
smart_toy_bear
|
The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 802.11 network's coverage area and entering an accou…
|
CWE-287
Improper Authentication
|
CVE-2015-8269
|
2024-11-21 11:38 |
2016-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212069
|
7.5 |
HIGH
Network
|
huawei
|
e5151_firmware e5186_firmware
|
Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with software before V200R001B310D01SP00C00 allow DNS query packets using the static source…
|
CWE-20
Improper Input Validation
|
CVE-2015-8265
|
2024-11-21 11:38 |
2016-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212070
|
7.5 |
HIGH
Network
|
opensuse golang
|
leap go
|
The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes it easier for attackers to obtain private RSA keys…
|
CWE-200
Information Exposure
|
CVE-2015-8618
|
2024-11-21 11:38 |
2016-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|