CWE-17 · 166 kayıt
DEPRECATED: Code
Bu sınıftaki CVE’ler
166 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
66Bu hafta | CVE-2015-0240Silahlaştırılmış | The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x beforsamba · samba · CWE-17 | Kritik10,0 | — | %88,0 | 23 Şub 2015 |
59Planlayın | CVE-2014-9222Silahlaştırılmış | AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gaallegrosoft · rompager · CWE-17 | Kritik10,0 | — | %63,7 | 24 Ara 2014 |
44Planlayın | CVE-2015-3292Kavram kanıtı | The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) senetapp · oncommand workflow automation · CWE-17 | Kritik10,0 | — | %12,2 | 31 May 2015 |
43Planlayın | CVE-2015-4335İstismar yok | Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.redislabs · redis · CWE-17 | Kritik10,0 | — | %9,5 | 9 Haz 2015 |
42Planlayın | CVE-2015-3183İstismar yok | The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remotapache · http server · CWE-17 | Orta5,0 | — | %73,3 | 20 Tem 2015 |
42Planlayın | CVE-2015-4620İstismar yok | name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNisc · bind · CWE-17 | Yüksek7,8 | — | %37,9 | 8 Tem 2015 |
42Planlayın | CVE-2015-1728İstismar yok | Microsoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "microsoft · windows media player · CWE-17 | Kritik9,3 | — | %17,6 | 9 Haz 2015 |
41Planlayın | CVE-2015-2737İstismar yok | The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.mozilla · firefox · CWE-17 | Kritik10,0 | — | %2,7 | 5 Tem 2015 |
41Planlayın | CVE-2015-2738İstismar yok | The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x bemozilla · firefox · CWE-17 | Kritik10,0 | — | %2,7 | 5 Tem 2015 |
41Planlayın | CVE-2015-2734İstismar yok | The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x befomozilla · firefox · CWE-17 | Kritik10,0 | — | %2,7 | 5 Tem 2015 |
41Planlayın | CVE-2015-5887İstismar yok | The TLS Handshake Protocol implementation in Secure Transport in Apple OS X before 10.11 accepts a Certificate Request message within a sessapple · mac os x · CWE-17 | Kritik10,0 | — | %2,5 | 9 Eki 2015 |
39İzleyin | CVE-2016-10481İstismar yok | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, Mqualcomm · mdm9607 firmware · CWE-17 | Kritik9,8 | — | %1,2 | 18 Nis 2018 |
38İzleyin | CVE-2014-9707Silahlaştırılmış | EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a .embedthis · goahead · CWE-17 | Yüksek7,5 | — | %28,2 | 31 Mar 2015 |
38İzleyin | CVE-2015-2735İstismar yok | nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unimozilla · firefox · CWE-17 | Kritik9,3 | — | %3,8 | 5 Tem 2015 |
38İzleyin | CVE-2015-2736İstismar yok | The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird mozilla · firefox · CWE-17 | Kritik9,3 | — | %3,8 | 5 Tem 2015 |
35İzleyin | CVE-2016-10142İstismar yok | An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages.ietf · ipv6 · CWE-17 | Yüksek8,6 | — | %2,8 | 14 Oca 2017 |
33İzleyin | CVE-2015-1465İstismar yok | The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period flinux · linux kernel · CWE-17 | Yüksek7,8 | — | %6,5 | 5 Nis 2015 |
33İzleyin | CVE-2015-1157Kavram kanıtı | CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Uniapple · iphone os · CWE-17 | Yüksek7,8 | — | %5,5 | 27 May 2015 |
33İzleyin | CVE-2015-1935İstismar yok | The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Wibm · db2 · CWE-17 | Yüksek8,0 | — | %3,5 | 19 Tem 2015 |
32İzleyin | CVE-2015-8027İstismar yok | Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, whicnodejs · node.js · CWE-17 | Yüksek7,5 | — | %5,4 | 2 Oca 2016 |
32İzleyin | CVE-2015-1233İstismar yok | Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attagoogle · chrome · CWE-17 | Yüksek7,5 | — | %5,3 | 1 Nis 2015 |
32İzleyin | CVE-2015-0847İstismar yok | nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a dencanonical · ubuntu linux · CWE-17 | Yüksek7,8 | — | %3,1 | 29 May 2015 |
32İzleyin | CVE-2014-6386İstismar yok | Juniper Junos 11.4 before 11.4R8, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47juniper · junos · CWE-17 | Yüksek7,8 | — | %2,7 | 16 Oca 2015 |
32İzleyin | CVE-2015-1452İstismar yok | The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers tofortinet · fortios · CWE-17 | Yüksek7,8 | — | %1,8 | 2 Şub 2015 |
31İzleyin | CVE-2015-2743İstismar yok | PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workermozilla · firefox · CWE-17 | Yüksek7,5 | — | %4,7 | 5 Tem 2015 |
- CVE-2015-024066Bu hafta
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x befor
KritikCVSS 10,0SilahlaştırılmışEPSS %88samba · samba23 Şub 2015
- CVE-2014-922259Planlayın
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to ga
KritikCVSS 10,0SilahlaştırılmışEPSS %64allegrosoft · rompager24 Ara 2014
- CVE-2015-329244Planlayın
The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) se
KritikCVSS 10,0Kavram kanıtıEPSS %12netapp · oncommand workflow automation31 May 2015
- CVE-2015-433543Planlayın
Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
KritikCVSS 10,0İstismar yokEPSS %9redislabs · redis9 Haz 2015
- CVE-2015-318342Planlayın
The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remot
OrtaCVSS 5,0İstismar yokEPSS %73apache · http server20 Tem 2015
- CVE-2015-462042Planlayın
name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DN
YüksekCVSS 7,8İstismar yokEPSS %38isc · bind8 Tem 2015
- CVE-2015-172842Planlayın
Microsoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "
KritikCVSS 9,3İstismar yokEPSS %18microsoft · windows media player9 Haz 2015
- CVE-2015-273741Planlayın
The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.
KritikCVSS 10,0İstismar yokEPSS %3mozilla · firefox5 Tem 2015
- CVE-2015-273841Planlayın
The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x be
KritikCVSS 10,0İstismar yokEPSS %3mozilla · firefox5 Tem 2015
- CVE-2015-273441Planlayın
The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x befo
KritikCVSS 10,0İstismar yokEPSS %3mozilla · firefox5 Tem 2015
- CVE-2015-588741Planlayın
The TLS Handshake Protocol implementation in Secure Transport in Apple OS X before 10.11 accepts a Certificate Request message within a sess
KritikCVSS 10,0İstismar yokEPSS %2apple · mac os x9 Eki 2015
- CVE-2016-1048139İzleyin
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, M
KritikCVSS 9,8İstismar yokEPSS %1qualcomm · mdm9607 firmware18 Nis 2018
- CVE-2014-970738İzleyin
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a .
YüksekCVSS 7,5SilahlaştırılmışEPSS %28embedthis · goahead31 Mar 2015
- CVE-2015-273538İzleyin
nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses uni
KritikCVSS 9,3İstismar yokEPSS %4mozilla · firefox5 Tem 2015
- CVE-2015-273638İzleyin
The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird
KritikCVSS 9,3İstismar yokEPSS %4mozilla · firefox5 Tem 2015
- CVE-2016-1014235İzleyin
An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages.
YüksekCVSS 8,6İstismar yokEPSS %3ietf · ipv614 Oca 2017
- CVE-2015-146533İzleyin
The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period f
YüksekCVSS 7,8İstismar yokEPSS %6linux · linux kernel5 Nis 2015
- CVE-2015-115733İzleyin
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Uni
YüksekCVSS 7,8Kavram kanıtıEPSS %6apple · iphone os27 May 2015
- CVE-2015-193533İzleyin
The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and W
YüksekCVSS 8,0İstismar yokEPSS %4ibm · db219 Tem 2015
- CVE-2015-802732İzleyin
Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, whic
YüksekCVSS 7,5İstismar yokEPSS %5nodejs · node.js2 Oca 2016
- CVE-2015-123332İzleyin
Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote atta
YüksekCVSS 7,5İstismar yokEPSS %5google · chrome1 Nis 2015
- CVE-2015-084732İzleyin
nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a den
YüksekCVSS 7,8İstismar yokEPSS %3canonical · ubuntu linux29 May 2015
- CVE-2014-638632İzleyin
Juniper Junos 11.4 before 11.4R8, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47
YüksekCVSS 7,8İstismar yokEPSS %3juniper · junos16 Oca 2015
- CVE-2015-145232İzleyin
The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to
YüksekCVSS 7,8İstismar yokEPSS %2fortinet · fortios2 Şub 2015
- CVE-2015-274331İzleyin
PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Worker
YüksekCVSS 7,5İstismar yokEPSS %5mozilla · firefox5 Tem 2015