Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2015-12-29 CVE-2015-3223 Resource Management Errors vulnerability in Samba
The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles certain zero values, which allows remote attackers to cause a denial of service (infinite loop) via crafted packets.
network
low complexity
samba CWE-399
5.3
2015-12-29 CVE-2015-7786 Cross-site Scripting vulnerability in Nttdata web Analytics Service
Cross-site scripting (XSS) vulnerability in the NTT DATA Smart Sourcing JavaScript module 2003-11-26 through 2013-07-09 for Web Analytics Service allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
nttdata CWE-79
6.1
2015-12-28 CVE-2015-6852 Information Exposure vulnerability in EMC Secure Remote Services 3.0/3.02/3.03
Directory traversal vulnerability in the API in EMC Secure Remote Services Virtual Edition 3.x before 3.10 allows remote authenticated users to read log files via a crafted parameter.
network
low complexity
emc CWE-200
4.3
2015-12-28 CVE-2015-8660 Permissions, Privileges, and Access Controls vulnerability in Linux Kernel
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.
local
low complexity
linux CWE-264
6.7
2015-12-28 CVE-2015-8374 Information Exposure vulnerability in Linux Kernel
fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.
local
low complexity
linux CWE-200
4.0
2015-12-28 CVE-2015-7990 Race Condition vulnerability in Linux Kernel
Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.
local
high complexity
linux CWE-362
5.8
2015-12-28 CVE-2015-7509 Improper Input Validation vulnerability in Linux Kernel
fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.
local
low complexity
linux CWE-20
4.4
2015-12-28 CVE-2013-7446 Unspecified vulnerability in Linux Kernel
Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel before 4.3.3 allows local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls.
local
high complexity
linux
5.3
2015-12-27 CVE-2015-7783 Cross-site Scripting vulnerability in Let'S PHP! Pbbs 4.05
Cross-site scripting (XSS) vulnerability in Let's PHP! p++BBS before 4.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
let-s-php CWE-79
6.1
2015-12-27 CVE-2015-7665 Information Exposure vulnerability in Tails Project Tails 1.6
Tails before 1.7 includes the wget program but does not prevent automatic fallback from passive FTP to active FTP, which allows remote FTP servers to discover the Tor client IP address by reading a (1) PORT or (2) EPRT command.
network
low complexity
tails-project CWE-200
5.3