CVE-2015-0235
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
Published:Jan 27, 2015
Last Modified:Apr 12, 2025
EPS:Jan 28, 2015
EPSS Score:0.85843
CVSS Score:10
Affected Products
Vendor
Product
Action
Vendor
Apple
Product
Mac Os X
Apple
Mac Os X
Vendor
Debian
Product
Debian Linux
Debian
Debian Linux
Vendor
Gnu
Product
Glibc
Gnu
Glibc
Vendor
Ibm
Product
Pureapplication System
Ibm
Pureapplication System
Vendor
Ibm
Product
Security Access Manager For Enterprise Single Sign-on
Ibm
Security Access Manager For Enterprise Single Sign-on
Vendor
Oracle
Product
Communications Application Session Controller
Oracle
Communications Application Session Controller
Vendor
Oracle
Product
Communications Eagle Application Processor
Oracle
Communications Eagle Application Processor
Vendor
Oracle
Product
Communications Eagle Lnp Application Processor
Oracle
Communications Eagle Lnp Application Processor
Vendor
Oracle
Product
Communications Lsms
Oracle
Communications Lsms
Vendor
Oracle
Product
Communications Policy Management
Oracle
Communications Policy Management
Vendor
Oracle
Product
Communications Session Border Controller
Oracle
Communications Session Border Controller
Vendor
Oracle
Product
Communications User Data Repository
Oracle
Communications User Data Repository
Vendor
Oracle
Product
Communications Webrtc Session Controller
Oracle
Communications Webrtc Session Controller
Vendor
Oracle
Product
Exalogic Infrastructure
Oracle
Exalogic Infrastructure
Vendor
Oracle
Product
Linux
Oracle
Linux
Vendor
Oracle
Product
Vm Virtualbox
Oracle
Vm Virtualbox
Vendor
Php
Product
Php
Php
Php
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Rhel Els
Redhat
Rhel Els
Vendor
Redhat
Product
Rhel Eus
Redhat
Rhel Eus
Vendor
Redhat
Product
Rhel Mission Critical
Redhat
Rhel Mission Critical
Vendor
Redhat
Product
Virtualization
Redhat
Virtualization
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
