CVE-2015-5235
- EPSS 0.94%
- Veröffentlicht 09.10.2015 14:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
CVE-2015-5234
- EPSS 0.92%
- Veröffentlicht 09.10.2015 14:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web ...
CVE-2015-5400
- EPSS 24.7%
- Veröffentlicht 28.09.2015 20:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.
CVE-2015-6938
- EPSS 0.86%
- Veröffentlicht 21.09.2015 19:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: ...
CVE-2015-6665
- EPSS 0.82%
- Veröffentlicht 24.08.2015 14:59:22
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML el...
- EPSS 1.17%
- Veröffentlicht 24.08.2015 14:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. ...
CVE-2015-4491
- EPSS 3.69%
- Veröffentlicht 16.08.2015 01:59:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers t...
- EPSS 2.05%
- Veröffentlicht 14.08.2015 18:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
CVE-2015-5166
- EPSS 0.07%
- Veröffentlicht 12.08.2015 14:59:25
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice.
CVE-2015-5165
- EPSS 13.17%
- Veröffentlicht 12.08.2015 14:59:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.