Oracle

Solaris

546 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.98%
  • Published 06.07.2015 02:00:56
  • Last modified 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or poss...

  • EPSS 1.74%
  • Published 06.07.2015 02:00:55
  • Last modified 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and appli...

  • EPSS 2.29%
  • Published 06.07.2015 02:00:54
  • Last modified 12.04.2025 10:46:40

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XM...

Exploit
  • EPSS 0.61%
  • Published 06.07.2015 02:00:49
  • Last modified 12.04.2025 10:46:40

Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS sta...

  • EPSS 2.4%
  • Published 24.06.2015 14:59:01
  • Last modified 12.04.2025 10:46:40

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, a...

Exploit
  • EPSS 75.52%
  • Published 09.06.2015 18:59:06
  • Last modified 12.04.2025 10:46:40

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form ...

Exploit
  • EPSS 38.96%
  • Published 09.06.2015 18:59:03
  • Last modified 12.04.2025 10:46:40

The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or p...

Exploit
  • EPSS 28.15%
  • Published 09.06.2015 18:59:02
  • Last modified 12.04.2025 10:46:40

Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) ph...

Exploit
  • EPSS 18.05%
  • Published 09.06.2015 14:59:01
  • Last modified 12.04.2025 10:46:40

mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.

Exploit
  • EPSS 1.72%
  • Published 27.05.2015 10:59:06
  • Last modified 12.04.2025 10:46:40

The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value ...