- EPSS 0.86%
- Veröffentlicht 16.12.2015 11:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 might allow remote attackers to obtain sensitive information, cause a denial of service, or possibly have unspecified o...
CVE-2015-7204
- EPSS 1.72%
- Veröffentlicht 16.12.2015 11:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Mozilla Firefox before 43.0 does not properly store the properties of unboxed objects, which allows remote attackers to execute arbitrary code via crafted JavaScript variable assignments.
- EPSS 1.66%
- Veröffentlicht 16.12.2015 11:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontList.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via a craft...
- EPSS 1.91%
- Veröffentlicht 16.12.2015 11:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
- EPSS 1.58%
- Veröffentlicht 16.12.2015 11:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...
CVE-2015-3196
- EPSS 7.44%
- Veröffentlicht 06.12.2015 20:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (...
CVE-2015-3195
- EPSS 3.48%
- Veröffentlicht 06.12.2015 20:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to ob...
CVE-2015-8393
- EPSS 0.72%
- Veröffentlicht 02.12.2015 01:59:17
- Zuletzt bearbeitet 06.05.2026 22:30:45
pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client.
CVE-2015-8391
- EPSS 6.4%
- Veröffentlicht 02.12.2015 01:59:15
- Zuletzt bearbeitet 06.05.2026 22:30:45
The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as...
CVE-2015-8390
- EPSS 2.87%
- Veröffentlicht 02.12.2015 01:59:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized memory read) or possibly have unspecified other impact via a crafted regular expression, as demonstra...