CVE-2015-8212
UnknownEPSS 3.23%
Last modified
CVE-2015-8212 is a vulnerability of currently unknown severity. CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.. EPSS estimates a 3.23% chance of exploitation in the next 30 days.
Description
CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netbsd | Netbsd | 6.0 |
| Netbsd | Netbsd | 6.0.1 |
| Netbsd | Netbsd | 6.0.2 |
| Netbsd | Netbsd | 6.0.3 |
| Netbsd | Netbsd | 6.0.4 |
| Netbsd | Netbsd | 6.0.5 |
| Netbsd | Netbsd | 6.0.6 |
| Netbsd | Netbsd | 6.1 |
| Netbsd | Netbsd | 6.1.1 |
| Netbsd | Netbsd | 6.1.2 |
| Netbsd | Netbsd | 6.1.3 |
| Netbsd | Netbsd | 6.1.4 |
| Netbsd | Netbsd | 6.1.5 |
| Netbsd | Netbsd | 7.0 |
References
- http://www.securitytracker.com/id/1035673Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035673Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-8212?
CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.
How severe is CVE-2015-8212?
Severity scoring for CVE-2015-8212 is pending analysis. The EPSS model estimates a 3.23% probability of exploitation in the next 30 days.
How do I fix CVE-2015-8212?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-8206Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-8207Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-8208Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-8209Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-8210Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-8211Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-8213The get_format function in utils/formats.py in Django before…
- CVE-2015-8214A vulnerability has been identified in SIMATIC NET CP 342-5 …
- CVE-2015-8215net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel be…
- CVE-2015-8216The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c …
- CVE-2015-8217The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FF…
- CVE-2015-8218The decode_uncompressed function in libavcodec/faxcompr.c in…
Are you affected by CVE-2015-8212?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
