CVE-2015-2730
- EPSS 0.31%
- Published 06.07.2015 02:01:01
- Last modified 12.04.2025 10:46:40
Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which...
- EPSS 1.74%
- Published 06.07.2015 02:00:55
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and appli...
CVE-2015-2721
- EPSS 0.61%
- Published 06.07.2015 02:00:49
- Last modified 12.04.2025 10:46:40
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS sta...
CVE-2015-3202
- EPSS 0.31%
- Published 02.07.2015 21:59:03
- Last modified 12.04.2025 10:46:40
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's ...
CVE-2015-3234
- EPSS 0.5%
- Published 22.06.2015 19:59:02
- Last modified 12.04.2025 10:46:40
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange provide...
- EPSS 0.45%
- Published 22.06.2015 19:59:00
- Last modified 12.04.2025 10:46:40
The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
CVE-2015-3232
- EPSS 0.44%
- Published 22.06.2015 19:59:00
- Last modified 12.04.2025 10:46:40
Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destinations parameter.
CVE-2015-3429
- EPSS 1.53%
- Published 17.06.2015 18:59:03
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.
CVE-2015-3209
- EPSS 5.35%
- Published 15.06.2015 15:59:00
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
CVE-2015-4171
- EPSS 1.01%
- Published 10.06.2015 18:59:09
- Last modified 12.04.2025 10:46:40
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is...