CVE-2015-3666
- EPSS 3.24%
- Veröffentlicht 03.07.2015 01:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability t...
CVE-2015-3663
- EPSS 3.24%
- Veröffentlicht 03.07.2015 01:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability t...
CVE-2015-3662
- EPSS 3.24%
- Veröffentlicht 03.07.2015 01:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability t...
CVE-2015-3661
- EPSS 3.24%
- Veröffentlicht 03.07.2015 01:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability t...
CVE-2015-3659
- EPSS 1.11%
- Veröffentlicht 03.07.2015 01:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict access to SQL functions, which allows re...
CVE-2015-3658
- EPSS 0.27%
- Veröffentlicht 03.07.2015 01:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Page Loading functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly consider redirects during decisions about sending an Origin header, w...
- EPSS 16.94%
- Veröffentlicht 09.06.2015 18:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property is a string, which allows remote attackers to obtain sensitive information by providing crafted seria...
CVE-2015-4147
- EPSS 50.79%
- Veröffentlicht 09.06.2015 18:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_headers is an array, which allows remote attackers to execute arbitrary code by providing crafted serial...
CVE-2015-4026
- EPSS 10.31%
- Veröffentlicht 09.06.2015 18:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files wi...
CVE-2015-4025
- EPSS 6.08%
- Veröffentlicht 09.06.2015 18:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with...