CVE-2015-0811
- EPSS 0.87%
- Veröffentlicht 01.04.2015 10:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation.
- EPSS 0.8%
- Veröffentlicht 01.04.2015 10:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote attackers to cause a denial of se...
CVE-2015-0806
- EPSS 1.91%
- Veröffentlicht 01.04.2015 10:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which al...
CVE-2015-0805
- EPSS 1.91%
- Veröffentlicht 01.04.2015 10:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execut...
CVE-2015-0804
- EPSS 1.91%
- Veröffentlicht 01.04.2015 10:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers to execute arbitrary code or c...
CVE-2015-0803
- EPSS 1.91%
- Veröffentlicht 01.04.2015 10:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary c...
- EPSS 80.39%
- Veröffentlicht 01.04.2015 10:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content...
- EPSS 30.44%
- Veröffentlicht 01.04.2015 02:00:35
- Zuletzt bearbeitet 06.05.2026 22:30:45
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial ...
CVE-2015-2305
- EPSS 32.92%
- Veröffentlicht 30.03.2015 10:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary co...
CVE-2015-2301
- EPSS 11.21%
- Veröffentlicht 30.03.2015 10:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an a...