CVE-2015-8995
published 2017-05-16CVE-2015-8995: In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.
PriorityP433high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.61%
44.9th percentile
In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| qualcomm_inc | all_qualcomm_products | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2015-8995: Android Security Bulletin 2017-04-01
CVE: CVE-2015-8995
Severity: CRITICAL
References: A-35445002**
vendor_android·2017-04-01·CVSS 7.8
CVE-2015-8995 [HIGH] CVE-2015-8995: Android Security Bulletin 2017-04-01
CVE: CVE-2015-8995
Severity: CRITICAL
References: A-35445002**
Android Security Bulletin 2017-04-01
CVE: CVE-2015-8995
Severity: CRITICAL
References: A-35445002**
GHSA
GHSA-vpff-8r4f-x753: In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel
ghsa_unreviewed·2022-05-17
CVE-2015-8995 [HIGH] CWE-190 GHSA-vpff-8r4f-x753: In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel
In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.
No detection rules found.
Nuclei
Swim Team <= v1.44.10777 - Local File Inclusion
nuclei·CVSS 5.3
CVE-2015-5471 [MEDIUM] Swim Team <= v1.44.10777 - Local File Inclusion
Swim Team <= v1.44.10777 - Local File Inclusion
The program /wp-swimteam/include/user/download.php allows unauthenticated attackers to retrieve arbitrary files from the system.
Template:
id: CVE-2015-5471
info:
name: Swim Team <= v1.44.10777 - Local File Inclusion
author: 0x_Akoko
severity: medium
description: The program /wp-swimteam/include/user/download.php allows unauthenticated attackers to retrieve arbitrary files from the system.
impact: |
An attacker can exploit this vulnerability to read sensitive information from the server, such as database credentials, and potentially execute arbitrary code.
remediation: Upgrade to Swim Team version 1.45 or newer.
reference:
- https://wpscan.com/vulnerability/b00d9dda-721d-4204-8995-093f695c3568
- http://www.vapid.dhs.org/advisory.php?v=134
No writeups or analysis indexed.
2017-05-16
Published