|
271181
|
7.5 |
HIGH
Network
|
pcre ibm
|
pcre2 pcre powerkvm
|
PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expr…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3217
|
2024-11-21 11:28 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271182
|
9.8 |
CRITICAL
Network
|
pcre
|
pcre2 pcre
|
Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)…
|
CWE-787
Out-of-bounds Write
|
CVE-2015-3210
|
2024-11-21 11:28 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271183
|
5.5 |
MEDIUM
Local
|
pivotal_software vmware fedoraproject
|
spring_framework fedora
|
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of servi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3192
|
2024-11-21 11:28 |
2016-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271184
|
5.9 |
MEDIUM
Network
|
oracle mariadb fedoraproject debian redhat php
|
mysql mysql_connector\/c mariadb fedora debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_eus enterprise_linux_ser…
|
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle atta…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-3152
|
2024-11-21 11:28 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271185
|
7.5 |
HIGH
Network
|
libssh canonical debian fedoraproject
|
libssh ubuntu_linux debian_linux fedora
|
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (…
|
NVD-CWE-Other
|
CVE-2015-3146
|
2024-11-21 11:28 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271186
|
5.9 |
MEDIUM
Network
|
erlang oracle opensuse
|
erlang\/otp solaris opensuse
|
Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle …
|
CWE-200
Information Exposure
|
CVE-2015-2774
|
2024-11-21 11:28 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271187
|
5.9 |
MEDIUM
Network
|
oracle openssl
|
tuxedo exalogic_infrastructure peoplesoft_enterprise_peopletools openssl oss_support_tools vm_virtualbox
|
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection…
|
CWE-310 CWE-200
Cryptographic Issues Information Exposure
|
CVE-2015-3197
|
2024-11-21 11:28 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271188
|
9.8 |
CRITICAL
Network
|
apache
|
cloudstack
|
Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.
|
CWE-255
Credentials Management
|
CVE-2015-3252
|
2024-11-21 11:28 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271189
|
4.9 |
MEDIUM
Network
|
apache
|
cloudstack
|
Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API ca…
|
CWE-200
Information Exposure
|
CVE-2015-3251
|
2024-11-21 11:28 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271190
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, which allows remote attackers to cause a denial of ser…
|
CWE-20
Improper Input Validation
|
CVE-2015-3182
|
2024-11-21 11:28 |
2016-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|