CVE-2015-5234
- EPSS 0.92%
- Veröffentlicht 09.10.2015 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web ...
CVE-2014-9751
- EPSS 9.65%
- Veröffentlicht 06.10.2015 01:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packe...
CVE-2014-9750
- EPSS 10.16%
- Veröffentlicht 06.10.2015 01:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field...
CVE-2015-3247
- EPSS 0.77%
- Veröffentlicht 08.09.2015 15:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via un...
CVE-2015-5157
- EPSS 0.22%
- Veröffentlicht 31.08.2015 10:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution, which might allow local users to gain privileges by triggering an NMI.
CVE-2015-3214
- EPSS 1.47%
- Veröffentlicht 31.08.2015 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an inva...
CVE-2015-5165
- EPSS 10.86%
- Veröffentlicht 12.08.2015 14:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
CVE-2015-4495
- EPSS 69.92%
- Veröffentlicht 08.08.2015 00:59:04
- Zuletzt bearbeitet 30.07.2025 03:15:45
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript...
CVE-2015-4757
- EPSS 0.51%
- Veröffentlicht 16.07.2015 11:00:51
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier and 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
- EPSS 0.36%
- Veröffentlicht 16.07.2015 11:00:46
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to Server : I_S.