Oracle

Solaris

546 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 19.03.2014 10:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecifi...

  • EPSS 0.61%
  • Veröffentlicht 19.03.2014 10:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted ...

  • EPSS 2.08%
  • Veröffentlicht 19.03.2014 10:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted ap...

  • EPSS 0.94%
  • Veröffentlicht 19.03.2014 10:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathnam...

  • EPSS 0.22%
  • Veröffentlicht 26.02.2014 14:55:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML d...

  • EPSS 0.64%
  • Veröffentlicht 10.02.2014 18:15:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user a...

  • EPSS 0.43%
  • Veröffentlicht 10.02.2014 18:15:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user i...

  • EPSS 1.09%
  • Veröffentlicht 06.02.2014 05:44:25
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation...

  • EPSS 1.25%
  • Veröffentlicht 06.02.2014 05:44:25
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.

  • EPSS 1.23%
  • Veröffentlicht 06.02.2014 05:44:24
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via v...