Oracle

Solaris

553 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 65.04%
  • Veröffentlicht 15.04.2014 10:55:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a s...

Exploit
  • EPSS 12.42%
  • Veröffentlicht 21.03.2014 14:55:12
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.

  • EPSS 0.56%
  • Veröffentlicht 19.03.2014 10:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via u...

  • EPSS 0.55%
  • Veröffentlicht 19.03.2014 10:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger gene...

  • EPSS 0.61%
  • Veröffentlicht 19.03.2014 10:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.

  • EPSS 2.26%
  • Veröffentlicht 19.03.2014 10:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.

  • EPSS 0.23%
  • Veröffentlicht 19.03.2014 10:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.

  • EPSS 0.28%
  • Veröffentlicht 19.03.2014 10:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecifi...

  • EPSS 0.61%
  • Veröffentlicht 19.03.2014 10:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted ...

  • EPSS 1.54%
  • Veröffentlicht 19.03.2014 10:55:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted ap...