CVE-2015-2549
published 2015-10-14CVE-2015-2549: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows…
PriorityP431high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
2.34%
81.7th percentile
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - October 2015
blogs_talos·2015-10-13·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - October 2015
## Microsoft Patch Tuesday - October 2015
Microsoft's Patch Tuesday has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release is fairly light with a total of 6 bulletins released addressing 33 vulnerabilities. Half of the bulletins are rated "Critical" and address vulnerabilities in Internet Explorer, JScript/VBScript, and the Windows Shell. The other half of the bulletins are rated "Important" and address vulnerabilities in Edge, Office, and the Windows Kernel.
## Bulletins Rated Critical MS15-106, MS15-108, are MS15-109 are rated Critical in this month's release.
MS15-106 is this month's Internet Explorer security bulletin for versions 7 through 11. In total, 14 vulnerabil
Talos
Microsoft Patch Tuesday - October 2015
blogs_talos·2015-10-13·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - October 2015
Microsoft's Patch Tuesday has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release is fairly light with a total of 6 bulletins released addressing 33 vulnerabilities. Half of the bulletins are rated "Critical" and address vulnerabilities in Internet Explorer, JScript/VBScript, and the Windows Shell. The other half of the bulletins are rated "Important" and address vulnerabilities in Edge, Office, and the Windows Kernel.
### Bulletins Rated Critical MS15-106, MS15-108, are MS15-109 are rated Critical in this month's release.
MS15-106 is this month's Internet Explorer security bulletin for versions 7 through 11. In total, 14 vulnerabilities were addressed with most of them bei
Zscaler
Zscaler detects IE & MS Office Vulnerabilities | 10-13-2015
blogs_zscaler
Zscaler detects IE & MS Office Vulnerabilities | 10-13-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2015-7497 libxml2: Heap-based buffer overflow in xmlDictComputeFastQKey
bugzilla·2015-11-13·CVSS 5.0
CVE-2015-7497 [MEDIUM] CVE-2015-7497 libxml2: Heap-based buffer overflow in xmlDictComputeFastQKey
CVE-2015-7497 libxml2: Heap-based buffer overflow in xmlDictComputeFastQKey
A heap-based buffer overflow vulnerability was found in xmlDictComputeFastQKey in dict.c.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=756528
Discussion:
Created attachment 1093719
Proposed patch
---
Acknowledgments:
Name: the GNOME project
Upstream: Kostya Serebryany
---
Upstream commit:
https://git.gnome.org/browse/libxml2/commit/?id=6360a31a84efe69d155ed96306b9a931a40beab9
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2015:2549 https://rhn.redhat.com/errata/RHSA-2015-2549.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2015:2550 https://rhn.redhat.com/errata/RHSA-2015-2550.html
Bugzilla
CVE-2015-7498 libxml2: Heap-based buffer overflow in xmlParseXmlDecl
bugzilla·2015-11-13·CVSS 5.0
CVE-2015-7498 [MEDIUM] CVE-2015-7498 libxml2: Heap-based buffer overflow in xmlParseXmlDecl
CVE-2015-7498 libxml2: Heap-based buffer overflow in xmlParseXmlDecl
Heap-based buffer overflow was found in xmlParseXmlDecl. When conversion failure happens, parser continues to extract more errors which may lead to unexpected behaviour.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=756527
Upstream patch:
https://git.gnome.org/browse/libxml2/commit/?id=afd27c21f6b36e22682b7da20d726bce2dcb2f43
Discussion:
Acknowledgments:
Name: the GNOME project
Upstream: Kostya Serebryany
---
Upstream commit:
https://git.gnome.org/browse/libxml2/commit/?id=afd27c21f6b36e22682b7da20d726bce2dcb2f43
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2015:2549 https://rhn.redhat.com/errata/RHSA-2015-2549.html
---
This issue has been add
Bugzilla
CVE-2015-7500 libxml2: Heap buffer overflow in xmlParseMisc
bugzilla·2015-11-13·CVSS 5.0
CVE-2015-7500 [MEDIUM] CVE-2015-7500 libxml2: Heap buffer overflow in xmlParseMisc
CVE-2015-7500 libxml2: Heap buffer overflow in xmlParseMisc
A heap-based buffer overflow read in xmlParseMisc was found.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=756525
Discussion:
Created attachment 1093866
Upstream patch
---
Acknowledgments:
Name: the GNOME project
Upstream: Kostya Serebryany
---
Upstream commit:
https://git.gnome.org/browse/libxml2/commit/?id=f1063fdbe7fa66332bbb76874101c2a7b51b519f
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2015:2549 https://rhn.redhat.com/errata/RHSA-2015-2549.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2015:2550 https://rhn.redhat.com/errata/RHSA-2015-2550.html
---
This issue has been addressed in the fo
Bugzilla
CVE-2015-7499 libxml2: Heap-based buffer overflow in xmlGROW
bugzilla·2015-11-13·CVSS 5.0
CVE-2015-7499 [MEDIUM] CVE-2015-7499 libxml2: Heap-based buffer overflow in xmlGROW
CVE-2015-7499 libxml2: Heap-based buffer overflow in xmlGROW
A heap-based buffer overflow was found in xmlGROW allowing the attacker to read the memory out of bounds.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=756479
Discussion:
Created attachment 1093836
Upstream patch
---
Acknowledgments:
Name: the GNOME project
Upstream: Kostya Serebryany
---
Upstream commits:
https://git.gnome.org/browse/libxml2/commit/?id=28cd9cb747a94483f4aea7f0968d202c20bb4cfc
https://git.gnome.org/browse/libxml2/commit/?id=35bcb1d758ed70aa7b257c9c3b3ff55e54e3d0da
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2015:2549 https://rhn.redhat.com/errata/RHSA-2015-2549.html
---
This issue has been addressed in the following products:
Red Ha
Bugzilla
libxml2: Multiple out-of-bounds reads in xmlDictComputeFastKey.isra.2 and xmlDictAddString.isra.O
bugzilla·2015-11-13·CVSS 4.3
CVE-2015-7941 [MEDIUM] libxml2: Multiple out-of-bounds reads in xmlDictComputeFastKey.isra.2 and xmlDictAddString.isra.O
libxml2: Multiple out-of-bounds reads in xmlDictComputeFastKey.isra.2 and xmlDictAddString.isra.O
Multiple out-of-bounds reads were found in libxml2.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=757699
Discussion:
This is fixed by the 2 patches for CVE-2015-7941
Daniel
---
*** This bug has been marked as a duplicate of bug 1274222 ***
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2015:2549 https://rhn.redhat.com/errata/RHSA-2015-2549.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2015:2550 https://rhn.redhat.com/errata/RHSA-2015-2550.html
Bugzilla
CVE-2015-5312 libxml2: CPU exhaustion when processing specially crafted XML input
bugzilla·2015-10-30·CVSS 7.1
CVE-2015-5312 [HIGH] CVE-2015-5312 libxml2: CPU exhaustion when processing specially crafted XML input
CVE-2015-5312 libxml2: CPU exhaustion when processing specially crafted XML input
A vulnerability in libxml2 was found causing DoS by exhausting CPU when parsing specially crafted XML document.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=756733
Discussion:
Created attachment 1087984
Proposed patch
Patch proposed by Google Security Team.
---
Upstream commit:
https://git.gnome.org/browse/libxml2/commit/?id=69030714cde66d525a8884bda01b9e8f0abf8e1e
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2015:2549 https://rhn.redhat.com/errata/RHSA-2015-2549.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2015:2550 https://rhn.redhat.com/errata/RHSA-2015-2550.html
---
T
2015-10-14
Published