CVE
- Id
- 85272
- CVE No.
- CVE-2015-7995
- Status
- Candidate
- Description
- The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.
- Phase
- Assigned (20151028)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
752351 | 85272 | CVE-2015-7995 | MLIST:[oss-security] 20151027 CVE request: libxslt xsltStylePreCompute() type confusion DoS | View |
752352 | 85272 | CVE-2015-7995 | URL:http://www.openwall.com/lists/oss-security/2015/10/27/10 | View |
752353 | 85272 | CVE-2015-7995 | MLIST:[oss-security] 20151028 Re: CVE request: libxslt xsltStylePreCompute() type confusion DoS | View |
752354 | 85272 | CVE-2015-7995 | URL:http://www.openwall.com/lists/oss-security/2015/10/28/4 | View |
752355 | 85272 | CVE-2015-7995 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=1257962 | View |
752356 | 85272 | CVE-2015-7995 | CONFIRM:https://git.gnome.org/browse/libxslt/commit/?id=7ca19df892ca22d9314e95d59ce2abdeff46b617 | View |
752357 | 85272 | CVE-2015-7995 | CONFIRM:https://support.apple.com/HT205729 | View |
752358 | 85272 | CVE-2015-7995 | CONFIRM:https://support.apple.com/HT205731 | View |
752359 | 85272 | CVE-2015-7995 | CONFIRM:https://support.apple.com/HT205732 | View |
752360 | 85272 | CVE-2015-7995 | CONFIRM:https://support.apple.com/HT206168 | View |
752361 | 85272 | CVE-2015-7995 | CONFIRM:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017 | View |
752362 | 85272 | CVE-2015-7995 | CONFIRM:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380 | View |
752363 | 85272 | CVE-2015-7995 | CONFIRM:http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html | View |
752364 | 85272 | CVE-2015-7995 | APPLE:APPLE-SA-2016-01-19-1 | View |
752365 | 85272 | CVE-2015-7995 | URL:http://lists.apple.com/archives/security-announce/2016/Jan/msg00002.html | View |
752366 | 85272 | CVE-2015-7995 | APPLE:APPLE-SA-2016-01-19-2 | View |
752367 | 85272 | CVE-2015-7995 | URL:http://lists.apple.com/archives/security-announce/2016/Jan/msg00003.html | View |
752368 | 85272 | CVE-2015-7995 | APPLE:APPLE-SA-2016-01-25-1 | View |
752369 | 85272 | CVE-2015-7995 | URL:http://lists.apple.com/archives/security-announce/2016/Jan/msg00005.html | View |
752370 | 85272 | CVE-2015-7995 | APPLE:APPLE-SA-2016-03-21-2 | View |
752371 | 85272 | CVE-2015-7995 | URL:http://lists.apple.com/archives/security-announce/2016/Mar/msg00001.html | View |
752372 | 85272 | CVE-2015-7995 | DEBIAN:DSA-3605 | View |
752373 | 85272 | CVE-2015-7995 | URL:http://www.debian.org/security/2016/dsa-3605 | View |
752374 | 85272 | CVE-2015-7995 | SLACKWARE:SSA:2016-148-02 | View |
752375 | 85272 | CVE-2015-7995 | URL:http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.386546 | View |
752376 | 85272 | CVE-2015-7995 | SUSE:openSUSE-SU-2016:1439 | View |
752377 | 85272 | CVE-2015-7995 | URL:http://lists.opensuse.org/opensuse-updates/2016-05/msg00123.html | View |
752378 | 85272 | CVE-2015-7995 | BID:77325 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
10905 | JVNDB-2015-006225 | Adobe Flash Player および Adobe AIR における任意のコードを実行される脆弱性 | Adobe Flash Player および Adobe AIR には、任意のコードを実行される、またはサービス運用妨害 (メモリ破損) 状態にされる脆弱性が存在します。 | CVE-2015-8047 | 85272 | 10 | http://jvndb.jvn.jp/ja/contents/2015/JVNDB-2015-006225.html | View |