- EPSS 13.92%
- Published 13.05.2015 10:59:44
- Last modified 12.04.2025 10:46:40
Buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allows attackers to execute arbitrary code via unknown vectors.
- EPSS 12.26%
- Published 13.05.2015 10:59:43
- Last modified 12.04.2025 10:46:40
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-9161,...
- EPSS 49.31%
- Published 13.05.2015 10:59:00
- Last modified 12.04.2025 10:46:40
Multiple heap-based buffer overflows in Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to execute arbitrary code via unknown vectors.
- EPSS 7.24%
- Published 01.05.2015 15:59:05
- Last modified 12.04.2025 10:46:40
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
CVE-2015-3416
- EPSS 5.09%
- Published 24.04.2015 17:59:02
- Last modified 12.04.2025 10:46:40
The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-b...
CVE-2015-3415
- EPSS 7.08%
- Published 24.04.2015 17:59:01
- Last modified 12.04.2025 10:46:40
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact v...
CVE-2015-3414
- EPSS 7.08%
- Published 24.04.2015 17:59:00
- Last modified 12.04.2025 10:46:40
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other im...
- EPSS 1.71%
- Published 24.04.2015 14:59:11
- Last modified 12.04.2025 10:46:40
cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
CVE-2015-3145
- EPSS 63.65%
- Published 24.04.2015 14:59:10
- Last modified 12.04.2025 10:46:40
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via...
- EPSS 2.09%
- Published 24.04.2015 14:59:08
- Last modified 12.04.2025 10:46:40
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.