CVE-2015-3145
- EPSS 63.7%
- Veröffentlicht 24.04.2015 14:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via...
- EPSS 1.01%
- Veröffentlicht 24.04.2015 14:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via...
- EPSS 3.48%
- Veröffentlicht 24.04.2015 14:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
CVE-2014-9718
- EPSS 0.21%
- Veröffentlicht 21.04.2015 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite ...
CVE-2015-2041
- EPSS 0.07%
- Veröffentlicht 21.04.2015 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a s...
CVE-2015-3336
- EPSS 0.89%
- Veröffentlicht 19.04.2015 10:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 42.0.2311.90 does not always ask the user before proceeding with CONTENT_SETTINGS_TYPE_FULLSCREEN and CONTENT_SETTINGS_TYPE_MOUSELOCK changes, which allows user-assisted remote attackers to cause a denial of service (UI disruptio...
CVE-2015-3334
- EPSS 0.51%
- Veröffentlicht 19.04.2015 10:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
browser/ui/website_settings/website_settings.cc in Google Chrome before 42.0.2311.90 does not always display "Media: Allowed by you" in a Permissions table after the user has granted camera permission to a web site, which might make it easier for use...
CVE-2015-3333
- EPSS 0.26%
- Veröffentlicht 19.04.2015 10:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1249
- EPSS 1.5%
- Veröffentlicht 19.04.2015 10:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1248
- EPSS 0.55%
- Veröffentlicht 19.04.2015 10:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The FileSystem API in Google Chrome before 40.0.2214.91 allows remote attackers to bypass the SafeBrowsing for Executable Files protection mechanism by creating a .exe file in a temporary filesystem and then referencing this file with a filesystem:ht...