CVE-2015-6241
- EPSS 0.57%
- Veröffentlicht 24.08.2015 23:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree implementation in Wireshark 1.12.x before 1.12.7 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote attacker...
- EPSS 4.37%
- Veröffentlicht 24.08.2015 14:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) contrib.sessions.backends.base.SessionBase.flush and (2) cache_db.SessionStore.flush functions in Django 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions create empty sessions in certain circumstances, which allows remote...
- EPSS 5.34%
- Veröffentlicht 24.08.2015 14:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions allows remote attackers to cause a denial of service (session store consumption or session record remova...
CVE-2015-3219
- EPSS 0.41%
- Veröffentlicht 20.08.2015 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015.1.x before 2015.1.1 allows remote attackers to inject arbitrary web script or HTML via the description parame...
CVE-2015-4496
- EPSS 1.51%
- Veröffentlicht 16.08.2015 01:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.
CVE-2015-4493
- EPSS 7.31%
- Veröffentlicht 16.08.2015 01:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an invalid size field in an esds c...
CVE-2015-4492
- EPSS 2.31%
- Veröffentlicht 16.08.2015 01:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a SharedWorker object that makes recursive calls to the...
CVE-2015-4491
- EPSS 4.3%
- Veröffentlicht 16.08.2015 01:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers t...
CVE-2015-4490
- EPSS 0.34%
- Veröffentlicht 16.08.2015 01:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matchi...
CVE-2015-4489
- EPSS 2.2%
- Veröffentlicht 16.08.2015 01:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a se...