Vulnerability Database

289,689

Total vulnerabilities in the database

CVE-2015-3281

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.

  • Published: Jul 6, 2015
  • Updated: Apr 13, 2023
  • CVE: CVE-2015-3281
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:P/I:N/A:N

CWEs:

Software From Fixed in
debian / debian_linux 8.0 8.0.x
haproxy / haproxy 1.5.0 1.5.0.x
haproxy / haproxy 1.5.10 1.5.10.x
haproxy / haproxy 1.5.12 1.5.12.x
haproxy / haproxy 1.5-dev7 1.5-dev7.x
haproxy / haproxy 1.5-dev 1.5-dev.x
haproxy / haproxy 1.5.7 1.5.7.x
haproxy / haproxy 1.5.5 1.5.5.x
haproxy / haproxy 1.5.1 1.5.1.x
haproxy / haproxy 1.5.4 1.5.4.x
haproxy / haproxy 1.5-dev4 1.5-dev4.x
haproxy / haproxy 1.5-dev1 1.5-dev1.x
haproxy / haproxy 1.5.6 1.5.6.x
haproxy / haproxy 1.5-dev10 1.5-dev10.x
haproxy / haproxy 1.5-dev6 1.5-dev6.x
haproxy / haproxy 1.5-dev15 1.5-dev15.x
haproxy / haproxy 1.5-dev13 1.5-dev13.x
haproxy / haproxy 1.5-dev16 1.5-dev16.x
haproxy / haproxy 1.5-dev12 1.5-dev12.x
haproxy / haproxy 1.5.11 1.5.11.x
haproxy / haproxy 1.5-dev19 1.5-dev19.x
haproxy / haproxy 1.5-dev3 1.5-dev3.x
haproxy / haproxy 1.5-dev0 1.5-dev0.x
haproxy / haproxy 1.5.2 1.5.2.x
haproxy / haproxy 1.5-dev18 1.5-dev18.x
haproxy / haproxy 1.5-dev9 1.5-dev9.x
haproxy / haproxy 1.5.13 1.5.13.x
haproxy / haproxy 1.5-dev2 1.5-dev2.x
haproxy / haproxy 1.5-dev8 1.5-dev8.x
haproxy / haproxy 1.5.8 1.5.8.x
haproxy / haproxy 1.5-dev17 1.5-dev17.x
haproxy / haproxy 1.5-dev11 1.5-dev11.x
haproxy / haproxy 1.5-dev5 1.5-dev5.x
haproxy / haproxy 1.5.9 1.5.9.x
haproxy / haproxy 1.5-dev14 1.5-dev14.x
haproxy / haproxy 1.5.3 1.5.3.x
haproxy / haproxy 1.6-dev0 1.6-dev0.x
canonical / ubuntu_linux 14.10 14.10.x
canonical / ubuntu_linux 15.04 15.04.x
opensuse / opensuse 13.2 13.2.x
opensuse / openstack_cloud 5 5.x
redhat / enterprise_linux_desktop 7.0 7.0.x
redhat / enterprise_linux_workstation 7.0 7.0.x
redhat / enterprise_linux_server 7.0 7.0.x
redhat / enterprise_linux_server_eus 7.2 7.2.x
redhat / enterprise_linux_server_eus 7.1 7.1.x
redhat / enterprise_linux_server_tus 7.3 7.3.x
redhat / enterprise_linux_server_aus 7.3 7.3.x
redhat / enterprise_linux_server_aus 7.4 7.4.x
redhat / enterprise_linux_server_eus 7.3 7.3.x
redhat / enterprise_linux_server_eus 7.4 7.4.x
redhat / enterprise_linux_server_eus 7.5 7.5.x
redhat / enterprise_linux_server_tus 7.6 7.6.x
redhat / enterprise_linux_server_eus 7.6 7.6.x
redhat / enterprise_linux_server_aus 7.6 7.6.x
suse / linux_enterprise_high_availability_extension 12 12.x