CVE-2015-1941
published 2015-06-30CVE-2015-1941: The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to read arbitrary files via a crafted TCP packet to an unspecified…
PriorityP349high7.8CVSS 2.0
AVNACLAuNCCINAN
EPSS
5.96%
92.4th percentile
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to read arbitrary files via a crafted TCP packet to an unspecified port.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| protobuf | >= 0 < 2.6.1-1.3ubuntu0.1~esm2 | 2.6.1-1.3ubuntu0.1~esm2 | |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
| ibm | tivoli_storage_manager_fastback | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
protobuf vulnerabilities
osv·2022-12-08·CVSS 8.8
CVE-2015-5237 protobuf vulnerabilities
protobuf vulnerabilities
It was discovered that protobuf did not properly manage memory when serializing
large messages. An attacker could possibly use this issue to cause applications
using protobuf to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2015-5237)
It was discovered that protobuf did not properly manage memory when parsing
specifically crafted messages. An attacker could possibly use this issue to
cause applications using protobuf to crash, resulting in a denial of service.
(CVE-2022-1941)
GHSA
GHSA-fjxr-28c8-xp4f: The server in IBM Tivoli Storage Manager FastBack 6
ghsa_unreviewed·2022-05-17
CVE-2015-1941 [HIGH] CWE-200 GHSA-fjxr-28c8-xp4f: The server in IBM Tivoli Storage Manager FastBack 6
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to read arbitrary files via a crafted TCP packet to an unspecified port.
No detection rules found.
No public exploits indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg21959398http://www.securityfocus.com/bid/75446http://www.securitytracker.com/id/1032773http://www.zerodayinitiative.com/advisories/ZDI-15-268http://www-01.ibm.com/support/docview.wss?uid=swg21959398http://www.securityfocus.com/bid/75446http://www.securitytracker.com/id/1032773http://www.zerodayinitiative.com/advisories/ZDI-15-268
2015-06-30
Published