- EPSS 9.35%
- Veröffentlicht 10.04.2015 15:00:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.
CVE-2015-1317
- EPSS 1.44%
- Veröffentlicht 08.04.2015 18:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.
CVE-2015-1473
- EPSS 0.45%
- Veröffentlicht 08.04.2015 10:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers t...
CVE-2015-1472
- EPSS 4.76%
- Veröffentlicht 08.04.2015 10:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow)...
CVE-2015-0799
- EPSS 0.11%
- Veröffentlicht 08.04.2015 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2...
CVE-2015-1465
- EPSS 5.19%
- Veröffentlicht 05.04.2015 21:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period for redirecting lookups in the absence of caching, which allows remote attackers to cause a denial of service (...
CVE-2015-2756
- EPSS 0.12%
- Veröffentlicht 01.04.2015 14:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O ...
CVE-2015-0812
- EPSS 0.15%
- Veröffentlicht 01.04.2015 10:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DN...
CVE-2015-0811
- EPSS 0.77%
- Veröffentlicht 01.04.2015 10:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation.
- EPSS 0.71%
- Veröffentlicht 01.04.2015 10:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote attackers to cause a denial of se...