CVE-2015-1774
- EPSS 7.4%
- Veröffentlicht 28.04.2015 14:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-...
CVE-2015-3416
- EPSS 7.53%
- Veröffentlicht 24.04.2015 17:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-b...
CVE-2015-3415
- EPSS 7.94%
- Veröffentlicht 24.04.2015 17:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact v...
CVE-2015-3414
- EPSS 7.94%
- Veröffentlicht 24.04.2015 17:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other im...
- EPSS 1.42%
- Veröffentlicht 24.04.2015 14:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
CVE-2015-3310
- EPSS 1.73%
- Veröffentlicht 24.04.2015 14:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message ...
CVE-2015-3145
- EPSS 67.99%
- Veröffentlicht 24.04.2015 14:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via...
- EPSS 1.19%
- Veröffentlicht 24.04.2015 14:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via...
- EPSS 4.66%
- Veröffentlicht 24.04.2015 14:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
CVE-2015-3333
- EPSS 0.26%
- Veröffentlicht 19.04.2015 10:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.