CVE-2015-3246
CISA Adds Six Known Exploited Vulnerabilities to Catalog
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Coverage 1 source
-
2026-08-26
CISA Cybersecurity Advisories
high
CISA Adds Six Known Exploited Vulnerabilities to Catalog
CISA added six vulnerabilities to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation.
Mentioned with
CVE-2015-5287 CVE-2019-1068 CVE-2021-23758 CVE-2022-0995
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands