CVE-2015-1283
- EPSS 0.63%
- Published 23.07.2015 00:59:12
- Last modified 12.04.2025 10:46:40
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspec...
- EPSS 64.62%
- Published 16.07.2015 10:59:17
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability th...
CVE-2015-3209
- EPSS 5.35%
- Published 15.06.2015 15:59:00
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
- EPSS 52.59%
- Published 01.04.2015 02:00:35
- Last modified 12.04.2025 10:46:40
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial ...
- EPSS 1.24%
- Published 12.12.2013 18:55:10
- Last modified 11.04.2025 00:51:21
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that trigg...
- EPSS 90.51%
- Published 13.01.2010 19:30:00
- Last modified 09.04.2025 00:30:58
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMe...
CVE-2009-4324
- EPSS 92.89%
- Published 15.12.2009 02:30:00
- Last modified 09.04.2025 00:30:58
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZL...
CVE-2009-3620
- EPSS 0.07%
- Published 22.10.2009 16:00:00
- Last modified 09.04.2025 00:30:58
The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash...
CVE-2009-2910
- EPSS 0.05%
- Published 20.10.2009 17:30:00
- Last modified 09.04.2025 00:30:58
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 p...
CVE-2009-2903
- EPSS 3.77%
- Published 15.09.2009 22:30:00
- Last modified 09.04.2025 00:30:58
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (me...