CVE-2015-2304
- EPSS 2.98%
- Veröffentlicht 15.03.2015 19:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
CVE-2015-0254
- EPSS 3.81%
- Veröffentlicht 09.03.2015 14:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.
CVE-2015-2238
- EPSS 0.11%
- Veröffentlicht 09.03.2015 00:59:28
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1231
- EPSS 1.16%
- Veröffentlicht 09.03.2015 00:59:23
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
- EPSS 0.32%
- Veröffentlicht 09.03.2015 00:59:22
- Zuletzt bearbeitet 06.05.2026 22:30:45
net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection...
CVE-2015-1230
- EPSS 1.73%
- Veröffentlicht 09.03.2015 00:59:22
- Zuletzt bearbeitet 06.05.2026 22:30:45
The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly h...
CVE-2015-1228
- EPSS 1.07%
- Veröffentlicht 09.03.2015 00:59:21
- Zuletzt bearbeitet 06.05.2026 22:30:45
The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not initialize memory for a data structure, which allows r...
CVE-2015-1220
- EPSS 3.07%
- Veröffentlicht 09.03.2015 00:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have uns...
CVE-2015-1219
- EPSS 0.9%
- Veröffentlicht 09.03.2015 00:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vect...
CVE-2015-1218
- EPSS 1.07%
- Veröffentlicht 09.03.2015 00:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger movement ...