- EPSS 7.24%
- Veröffentlicht 30.03.2015 10:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extens...
CVE-2015-2301
- EPSS 17.29%
- Veröffentlicht 30.03.2015 10:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an a...
CVE-2014-8169
- EPSS 0.11%
- Veröffentlicht 18.03.2015 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environment variable values instead of the values for the user used to run the mapped program, which allows local users to gain privileges v...
CVE-2015-1231
- EPSS 1.16%
- Veröffentlicht 09.03.2015 00:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
- EPSS 0.32%
- Veröffentlicht 09.03.2015 00:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection...
CVE-2015-1228
- EPSS 1.07%
- Veröffentlicht 09.03.2015 00:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not initialize memory for a data structure, which allows r...
CVE-2015-0239
- EPSS 0.1%
- Veröffentlicht 02.03.2015 11:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering u...
- EPSS 2.9%
- Veröffentlicht 02.03.2015 11:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass in...
- EPSS 2.11%
- Veröffentlicht 08.02.2015 11:59:36
- Zuletzt bearbeitet 12.04.2025 10:46:40
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
CVE-2014-9674
- EPSS 5.12%
- Veröffentlicht 08.02.2015 11:59:35
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based bu...