CVE-2015-1256
- EPSS 2.14%
- Veröffentlicht 20.05.2015 10:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document that leverages improp...
CVE-2015-1255
- EPSS 1.58%
- Veröffentlicht 20.05.2015 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio implementation in Google Chrome before 43.0.2357.65 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unsp...
- EPSS 1.4%
- Veröffentlicht 20.05.2015 10:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remote attackers to bypass the Same Origin Policy by leveraging the availability of editing.
CVE-2015-1253
- EPSS 0.94%
- Veröffentlicht 20.05.2015 10:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that appends a child to a SCRIPT element,...
CVE-2015-1252
- EPSS 1.24%
- Veröffentlicht 20.05.2015 10:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, which allows remote attackers to bypass a sandbox protection mechanism or cause a denial of service (out-of-bounds write) via vectors that trigger ...
CVE-2015-1251
- EPSS 4.45%
- Veröffentlicht 20.05.2015 10:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the SpeechRecognitionClient implementation in the Speech subsystem in Google Chrome before 43.0.2357.65 allows remote attackers to execute arbitrary code via a crafted document.
CVE-2015-3427
- EPSS 0.44%
- Veröffentlicht 14.05.2015 14:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers to conduct SQL injection attacks via a \ (backslash) in a message. NOTE: this vulnerability exists be...
- EPSS 0.39%
- Veröffentlicht 14.05.2015 14:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The DER parser in Suricata before 2.0.8 allows remote attackers to cause a denial of service (crash) via vectors related to SSL/TLS certificates.
CVE-2015-0797
- EPSS 7.61%
- Veröffentlicht 14.05.2015 10:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbi...
- EPSS 4.98%
- Veröffentlicht 12.05.2015 19:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.