|
272361
|
- |
|
linux
|
linux_kernel
|
Race condition in net/sctp/socket.c in the Linux kernel before 4.1.2 allows local users to cause a denial of service (list corruption and panic) via a rapid series of system calls related to sockets,…
|
CWE-362
Race Condition
|
CVE-2015-3212
|
2024-11-21 11:28 |
2015-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272362
|
- |
|
type74
|
ed
|
Type74 ED before 4.0 misuses 128-bit ECB encryption for small files, which makes it easier for attackers to obtain plaintext data via differential cryptanalysis of a file with an original length smal…
|
CWE-17
Code
|
CVE-2015-2987
|
2024-11-21 11:28 |
2015-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272363
|
- |
|
libunwind_project
|
libunwind
|
Off-by-one error in the dwarf_to_unw_regnum function in include/dwarf_i.h in libunwind 1.1 allows local users to have unspecified impact via invalid dwarf opcodes.
|
CWE-189
Numeric Errors
|
CVE-2015-3239
|
2024-11-21 11:28 |
2015-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272364
|
- |
|
openstack
|
neutron
|
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) …
|
CWE-20
Improper Input Validation
|
CVE-2015-3221
|
2024-11-21 11:28 |
2015-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272365
|
- |
|
picketlink
|
picketlink
|
The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not properly check role based authorization, which allows remote au…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3158
|
2024-11-21 11:28 |
2015-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272366
|
6.5 |
MEDIUM
Network
|
linux-pam oracle
|
linux-pam sparc-opl_service_processor
|
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial …
|
CWE-200
Information Exposure
|
CVE-2015-3238
|
2024-11-21 11:28 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272367
|
- |
|
mobile_devices
|
c4_obd-ii_dongle_firmware
|
Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbit…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2015-2908
|
2024-11-21 11:28 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272368
|
- |
|
mobile_devices
|
c4_obd-ii_dongle_firmware
|
Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, have hardcoded SSH credentials, which makes it easier for remote attackers to ob…
|
NVD-CWE-Other
|
CVE-2015-2907
|
2024-11-21 11:28 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272369
|
- |
|
mobile_devices
|
c4_obd-ii_dongle_firmware
|
Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, store SSH private keys that are the same across different customers' installatio…
|
NVD-CWE-Other
|
CVE-2015-2906
|
2024-11-21 11:28 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272370
|
- |
|
actiontec
|
_ncs01_firmware
|
Cross-site request forgery (CSRF) vulnerability on Actiontec GT784WN modems with firmware before NCS01-1.0.13 allows remote attackers to hijack the authentication or intranet connectivity of arbitrar…
|
CWE-352
Origin Validation Error
|
CVE-2015-2905
|
2024-11-21 11:28 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|