CVE-2015-2616
published 2015-07-16CVE-2015-2616: Unspecified vulnerability in Oracle Sun Solaris 3.3 and 4.2 allows local users to affect availability via unknown vectors related to DevFS.
PriorityP413medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.38%
29.8th percentile
Unspecified vulnerability in Oracle Sun Solaris 3.3 and 4.2 allows local users to affect availability via unknown vectors related to DevFS.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | oracle_and_sun_systems_product_suite | — | — |
| oracle | oracle_and_sun_systems_product_suite | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3wq2-hvxm-x2c4: Unspecified vulnerability in Oracle Sun Solaris 3
ghsa_unreviewed·2022-05-17
CVE-2015-2616 [MEDIUM] GHSA-3wq2-hvxm-x2c4: Unspecified vulnerability in Oracle Sun Solaris 3
Unspecified vulnerability in Oracle Sun Solaris 3.3 and 4.2 allows local users to affect availability via unknown vectors related to DevFS.
Red Hat
php: HTTP response splitting in header() function
vendor_redhat·2015-02-03·CVSS 6.1
CVE-2015-8935 [MEDIUM] CWE-113 php: HTTP response splitting in header() function
php: HTTP response splitting in header() function
The sapi_header_op function in main/SAPI.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 supports deprecated line folding without considering browser compatibility, which allows remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer by leveraging (1) %0A%20 or (2) %0D%0A%20 mishandling in the header function.
The header() PHP function allowed header stings containing line break followed by a space or tab, as allowed by RFC 2616. Certain browsers handled the continuation line as new header, making it possible to conduct a HTTP response splitting attack against such browsers. The header() function was updated to follow RFC 7230 and not allow any line breaks.
Package: php (Red Hat Enterp
No detection rules found.
No public exploits indexed.
2015-07-16
Published