peter bassill · operator
$ cve CVE-2015-0235 JSON

CVE-2015-0235 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 94.6% (pctl 100)

Patch early

A public exploit exists.

Description

Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS94.56% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploityes
Published2015-01-28
Last modified2026-06-17

Affected (18)

VendorProduct
applemac os x
debiandebian linux
gnuglibc
ibmpureapplication system
ibmsecurity access manager for enterprise single sign-on
oraclecommunications application session controller
oraclecommunications eagle application processor
oraclecommunications eagle lnp application processor
oraclecommunications lsms
oraclecommunications policy management
oraclecommunications session border controller
oraclecommunications user data repository
oraclecommunications webrtc session controller
oracleexalogic infrastructure
oraclelinux
oraclevm virtualbox
phpphp
redhatvirtualization

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD