← All CVEs

CVE-2015-0235

high · 10

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

10
CVSS
94.6%
EPSS (exploit prob.)
100th
EPSS percentile
2015-01-28
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
gnuglibc>= 2.0, < 2.18
oraclecommunications_application_session_controller< 3.7.1
oraclecommunications_eagle_application_processor16.0
oraclecommunications_eagle_lnp_application_processor10.0
oraclecommunications_lsms13.1
oraclecommunications_policy_management9.7.3
oraclecommunications_policy_management9.9.1
oraclecommunications_policy_management10.4.1
oraclecommunications_policy_management11.5
oraclecommunications_policy_management12.1.1
oraclecommunications_session_border_controller< 7.2.0
oraclecommunications_session_border_controller7.2.0
oraclecommunications_session_border_controller8.0.0
oraclecommunications_user_data_repository>= 10.0.0, <= 10.0.1
oraclecommunications_webrtc_session_controller7.0
oraclecommunications_webrtc_session_controller7.1
oraclecommunications_webrtc_session_controller7.2
oracleexalogic_infrastructure1.0
oracleexalogic_infrastructure2.0
oraclevm_virtualbox< 5.1.24
oraclelinux5
oraclelinux7
debiandebian_linux7.0
debiandebian_linux8.0
redhatvirtualization6.0
applemac_os_x< 10.11.1
ibmpureapplication_system1.0.0.0
ibmpureapplication_system1.1.0.0
ibmpureapplication_system2.0.0.0
ibmsecurity_access_manager_for_enterprise_single_sign-on8.2
phpphp>= 5.4.0, < 5.4.38
phpphp>= 5.5.0, < 5.5.22
phpphp>= 5.6.0, < 5.6.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-0235