Search

Found 937 results in 148ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2015-2582 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to GIS.
CVE-2015-5144 medium 4.3 FIX ubuntu ubuntudebian debian djangoproject 11y ago Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP …
CVE-2015-3281 medium 5.0 FIX debian debianubuntu ubuntu rhel haproxy 11y ago The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitiv…
CVE-2015-2721 medium 4.3 FIX debian debianubuntu ubuntususe suse novellmozilla 11y ago Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not p…
CVE-2015-1330 medium 6.8 FIX ubuntu ubuntudebian debian debian 11y ago unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which all…
CVE-2015-1851 medium 6.8 FIX debian debianubuntu ubuntu openstack 11y ago OpenStack Cinder file disclosure in image convert
CVE-2015-3395 medium 6.8 FIX debian debianubuntu ubuntu ffmpeglibav 11y ago The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 all…
CVE-2015-4171 low 2.6 FIX debian debianubuntu ubuntu strongswan 11y ago strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication rest…
CVE-2015-4106 medium 4.6 FIX suse susedebian debianfedora fedora qemucitrix 11y ago QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host c…
CVE-2015-3165 medium 4.3 debian debianubuntu ubuntu postgresql 11y ago Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash…
CVE-2015-2830 low 1.9 FIX debian debian linux-kernelubuntu ubuntu 11y ago arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protectio…
CVE-2015-4000 low 3.7 4.7 EXPFIX slesdebian debianmacos macos opensslibmoracle 11y ago The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to c…
CVE-2015-3407 medium 5.0 FIX debian debianubuntu ubuntu module-signature_project 11y ago Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
CVE-2015-3451 medium 5.0 FIX debian debianubuntu ubuntususe suse xml-libxml_project 11y ago The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to t…
CVE-2015-2668 medium 5.0 FIX debian debianubuntu ubuntu clamav 11y ago ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file.
CVE-2015-2222 medium 5.0 FIX debian debianubuntu ubuntu clamav 11y ago ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file.
CVE-2015-2221 medium 5.0 FIX debian debianubuntu ubuntu clamav 11y ago ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.
CVE-2015-2170 medium 5.0 FIX debian debianubuntu ubuntu clamav 11y ago The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
CVE-2015-3153 medium 5.0 FIX debian debianubuntu ubuntumacos macos oraclehaxx 11y ago The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information…
CVE-2015-1322 medium 4.6 FIX debian debianubuntu ubuntu ubuntu 11y ago Directory traversal vulnerability in the Ubuntu network-manager package for Ubuntu (vivid) before 0.9.10.0-4ubuntu15.1, Ubuntu 14.10 before 0.9.8.8-0ubuntu28.1, and Ubuntu 14.04 LTS before 0.9.8.8-0u…
CVE-2015-1321 medium 6.8 ubuntu ubuntu oxide_project 11y ago Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webp…
CVE-2015-1863 medium 5.8 FIX slesubuntu ubuntudebian debian w1.fi 11y ago Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information…
CVE-2015-1774 medium 6.8 FIX debian debianubuntu ubuntu rhel apachelibreoffice 11y ago The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code vi…
CVE-2015-3310 medium 4.3 FIX ubuntu ubuntudebian debian point-to-point_protocol_project 11y ago Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial…
CVE-2015-3148 medium 5.0 FIX debian debianubuntu ubuntususe suse haxxhp 11y ago cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
CVE-2015-3143 medium 5.0 FIX debian debianubuntu ubuntumacos macos haxxhp 11y ago cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0…
CVE-2015-1244 medium 5.0 ubuntu ubuntudebian debian google 11y ago The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which…
CVE-2015-1241 medium 4.3 ubuntu ubuntudebian debian rhel google 11y ago Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintend…
CVE-2015-1240 medium 5.0 ubuntu ubuntudebian debian google 11y ago gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL p…
CVE-2015-1236 medium 4.3 ubuntu ubuntudebian debian google 11y ago The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allow…
CVE-2015-1235 medium 5.0 ubuntu ubuntudebian debian google 11y ago The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origi…
CVE-2015-1856 medium 5.5 FIX ubuntu ubuntudebian debian openstack 11y ago OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-vers…
CVE-2015-1852 medium 4.3 FIX ubuntu ubuntudebian debian openstack 11y ago The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configurat…
CVE-2015-2573 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
CVE-2015-2571 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
CVE-2015-2568 medium 5.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileg…
CVE-2015-0505 low 3.5 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
CVE-2015-0501 medium 5.7 ubuntu ubuntudebian debian rhel juniperoraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.
CVE-2015-0499 low 3.5 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Federated.
CVE-2015-0441 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Security …
CVE-2015-0433 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
CVE-2015-1819 medium 5.0 FIX debian debian rhelubuntu ubuntu xmlsoft 11y ago Nokogiri vulnerable to libxml XML Entity Expansion
CVE-2015-0840 medium 4.3 FIX debian debianubuntu ubuntu debian 11y ago The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).
CVE-2015-1473 medium 6.4 FIX debian debianubuntu ubuntu gnu 11y ago The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca functi…
CVE-2015-0799 medium 4.3 suse suseubuntu ubuntu mozilla 11y ago The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying tha…
CVE-2015-2756 medium 4.9 FIX ubuntu ubuntudebian debianfedora fedora 11y ago QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and …
CVE-2015-0812 medium 4.3 suse suseubuntu ubuntu mozilla 11y ago Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement …
CVE-2015-0811 medium 6.4 suse suseubuntu ubuntu mozilla 11y ago The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image …
CVE-2015-0808 medium 5.0 suse suseubuntu ubuntu mozilla 11y ago The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which m…
CVE-2015-0802 medium 6.0 EXP suse suseubuntu ubuntu mozilla 11y ago Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScr…
CVE-2015-2808 low 3.7 3.7 FIX slesdebian debian rhel oracleredhatsuse 11y ago The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to cond…
CVE-2015-2305 medium 6.8 FIX debian debiansuse suseubuntu ubuntu rxspencer_projectphp 11y ago Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow …
CVE-2014-9709 medium 5.0 FIX debian debiansuse suseubuntu ubuntu phplibgd 11y ago The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and applicati…
CVE-2014-8121 medium 5.0 FIX debian debiansuse suseubuntu ubuntu gnu 11y ago DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to …
CVE-2015-2316 medium 5.0 FIX fedora fedoraubuntu ubuntususe suse djangoproject 11y ago The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of servi…
CVE-2015-0250 medium 6.4 FIX slesdebian debianubuntu ubuntu apacheredhat 11y ago Improper Input Validation in Apache Batik
CVE-2015-2296 medium 6.8 FIX slesubuntu ubuntudebian debian python 11y ago The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
CVE-2014-8159 medium 6.9 FIX debian debian linux-kernelubuntu ubuntu 11y ago The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regi…
CVE-2015-2304 medium 6.4 FIX debian debianubuntu ubuntususe suse libarchive 11y ago Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
CVE-2015-1229 medium 5.0 rhelubuntu ubuntu google 11y ago net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allo…
CVE-2015-1220 medium 6.8 ubuntu ubuntu google 11y ago Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attacker…
CVE-2015-0228 medium 5.0 FIX debian debianubuntu ubuntususe suse apache 11y ago The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a…
CVE-2014-9683 low 3.6 FIX debian debianubuntu ubuntu linux-kernel 11y ago Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buf…
CVE-2015-0239 medium 4.4 FIX slesdebian debian rhel 11y ago The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a…
CVE-2014-9644 low 2.1 FIX debian debianubuntu ubuntu linux-kernel 11y ago The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the…
CVE-2014-8160 medium 5.0 FIX slesdebian debian rhel 11y ago net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite pr…
CVE-2013-7421 low 2.1 FIX debian debianubuntu ubuntu linux-kernel 11y ago The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different…
CVE-2015-0834 medium 4.3 ubuntu ubuntususe suse mozilla 11y ago The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to …
CVE-2015-0832 medium 5.0 ubuntu ubuntususe suse mozilla 11y ago Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and …
CVE-2015-0831 medium 6.8 rhelubuntu ubuntu mozilla 11y ago Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remo…
CVE-2015-0830 medium 5.0 ubuntu ubuntususe suse mozilla 11y ago The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation log, which allows remote attackers to cause a den…
CVE-2015-0829 medium 6.8 ubuntu ubuntususe suse mozilla 11y ago Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
CVE-2015-0826 medium 6.8 ubuntu ubuntususe suse mozilla 11y ago The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read of heap memory) …
CVE-2015-0825 medium 4.3 ubuntu ubuntususe suse mozilla 11y ago Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malf…
CVE-2015-0824 medium 5.0 ubuntu ubuntususe suse mozilla 11y ago The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of service (out-of-bounds write of zero values, and appl…
CVE-2015-0821 medium 6.8 ubuntu ubuntususe suse mozilla 11y ago Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unsp…
CVE-2015-0820 low 2.6 ubuntu ubuntususe suse mozilla 11y ago Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sa…
CVE-2015-0819 medium 4.3 ubuntu ubuntususe suse mozilla 11y ago The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking a…
CVE-2015-1572 medium 4.6 FIX slesdebian debianubuntu ubuntu e2fsprogs_project 11y ago Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as d…
CVE-2013-7423 medium 5.0 FIX slesdebian debianubuntu ubuntu gnu 11y ago The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended l…
CVE-2014-9679 medium 6.8 FIX slesdebian debianubuntu ubuntu apple 11y ago Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via a malformed compressed raster file, which trigger…
CVE-2015-0247 medium 4.6 FIX slesdebian debianubuntu ubuntu e2fsprogs_project 12y ago Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
CVE-2014-9675 medium 5.0 FIX debian debianubuntu ubuntu rhel freetype 12y ago bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the AS…
CVE-2014-9673 medium 6.8 FIX debian debian rhelubuntu ubuntu freetype 12y ago Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly…
CVE-2014-9672 medium 5.8 FIX debian debianubuntu ubuntususe suse freetype 12y ago Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from pr…
CVE-2014-9671 medium 4.3 FIX debian debian rhelubuntu ubuntu freetype 12y ago Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via…
CVE-2014-9670 medium 4.3 FIX debian debian rhelubuntu ubuntu freetype 12y ago Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dere…
CVE-2014-9669 medium 6.8 FIX debian debianubuntu ubuntususe suse freetype 12y ago Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other i…
CVE-2014-9667 medium 6.8 FIX debian debianubuntu ubuntususe suse freetype 12y ago sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of…
CVE-2014-9666 medium 6.8 FIX debian debianubuntu ubuntususe suse freetype 12y ago The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count value, which allows remote attackers to cause a den…
CVE-2014-9664 medium 6.8 FIX debian debianubuntu ubuntususe suse freetype 12y ago FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecifi…
CVE-2014-9636 medium 5.0 FIX ubuntu ubuntudebian debianfedora fedora unzip_project 12y ago unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip arc…
CVE-2015-1210 medium 5.0 ubuntu ubuntususe susemacos macos google 12y ago The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and b…
CVE-2015-0236 low 3.5 FIX slesubuntu ubuntususe suse redhat 12y ago libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (…
CVE-2014-7943 medium 5.0 ubuntu ubuntususe suse chromiumgoogle 12y ago Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
CVE-2015-0432 medium 4.0 ubuntu ubuntususe susedebian debian oraclemariadb 12y ago Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.
CVE-2015-0413 low 1.9 FIX ubuntu ubuntususe susedebian debian oracle 12y ago Unspecified vulnerability in Oracle Java SE 7u72 and 8u25 allows local users to affect integrity via unknown vectors related to Serviceability.
CVE-2015-0410 medium 5.0 FIX ubuntu ubuntususe susedebian debian oracle 12y ago Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows rem…
CVE-2015-0407 medium 5.0 FIX ubuntu ubuntudebian debianfedora fedora oracle 12y ago Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Swing.
CVE-2015-0400 medium 5.0 FIX ubuntu ubuntususe susedebian debian oracle 12y ago Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries.