CVE-2015-1241
- EPSS 2.19%
- Published 19.04.2015 10:59:05
- Last modified 12.04.2025 10:46:40
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts ...
- EPSS 1.36%
- Published 19.04.2015 10:59:04
- Last modified 12.04.2025 10:46:40
gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers a state inconsistency.
CVE-2015-1238
- EPSS 1.83%
- Published 19.04.2015 10:59:03
- Last modified 12.04.2025 10:46:40
Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
CVE-2015-1237
- EPSS 1.83%
- Published 19.04.2015 10:59:02
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service or possibly have unspecified other impa...
CVE-2015-1236
- EPSS 0.6%
- Published 19.04.2015 10:59:01
- Last modified 12.04.2025 10:46:40
The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy...
- EPSS 1.13%
- Published 19.04.2015 10:59:00
- Last modified 12.04.2025 10:46:40
The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origin Policy via a crafted HTML document with an IFRAME...
CVE-2015-2575
- EPSS 0.64%
- Published 16.04.2015 17:00:07
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in the MySQL Connectors component in Oracle MySQL 5.1.34 and earlier allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Connector/J.
- EPSS 0.41%
- Published 16.04.2015 17:00:05
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
- EPSS 0.41%
- Published 16.04.2015 17:00:04
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
- EPSS 4.02%
- Published 16.04.2015 17:00:02
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileges.