Search

Found 1,420 results in 649ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2015-1851 medium 6.8 FIX debian debianubuntu ubuntu openstack 11y ago OpenStack Cinder file disclosure in image convert
CVE-2015-3395 medium 6.8 FIX debian debianubuntu ubuntu ffmpeglibav 11y ago The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 all…
CVE-2015-3209 high 7.5 FIX ubuntu ubuntudebian debian rhel qemujuniperredhat 11y ago Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_…
CVE-2015-4171 low 2.6 FIX debian debianubuntu ubuntu strongswan 11y ago strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication rest…
CVE-2015-3905 high 7.5 FIX ubuntu ubuntudebian debian t1utils_project 11y ago Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font f…
CVE-2015-4004 high 8.5 FIX debian debian linux-kernelubuntu ubuntu 11y ago The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or caus…
CVE-2015-4106 medium 4.6 FIX suse susedebian debianfedora fedora qemucitrix 11y ago QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host c…
CVE-2015-4047 high 7.8 slesdebian debianfedora fedora ipsec-toolsf5 11y ago racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
CVE-2015-0847 high 7.8 FIX debian debianubuntu ubuntu wouter_verhelst 11y ago nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of service (deadlock) via unspecified vectors.
CVE-2015-3165 medium 4.3 debian debianubuntu ubuntu postgresql 11y ago Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash…
CVE-2015-2830 low 1.9 FIX debian debian linux-kernelubuntu ubuntu 11y ago arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protectio…
CVE-2015-4000 low 3.7 4.7 EXPFIX slesdebian debianmacos macos opensslibmoracle 11y ago The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to c…
CVE-2015-3409 high 7.2 FIX debian debianubuntu ubuntu module-signature_project 11y ago Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan h…
CVE-2015-3407 medium 5.0 FIX debian debianubuntu ubuntu module-signature_project 11y ago Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
CVE-2015-3451 medium 5.0 FIX debian debianubuntu ubuntususe suse xml-libxml_project 11y ago The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to t…
CVE-2015-2668 medium 5.0 FIX debian debianubuntu ubuntu clamav 11y ago ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted xz archive file.
CVE-2015-2222 medium 5.0 FIX debian debianubuntu ubuntu clamav 11y ago ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted petite packed file.
CVE-2015-2221 medium 5.0 FIX debian debianubuntu ubuntu clamav 11y ago ClamAV before 0.98.7 allows remote attackers to cause a denial of service (infinite loop) via a crafted y0da cryptor file.
CVE-2015-2170 medium 5.0 FIX debian debianubuntu ubuntu clamav 11y ago The upx decoder in ClamAV before 0.98.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
CVE-2015-3153 medium 5.0 FIX debian debianubuntu ubuntumacos macos oraclehaxx 11y ago The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information…
CVE-2015-1250 high 7.5 ubuntu ubuntudebian debian google 11y ago Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1243 high 7.5 ubuntu ubuntudebian debian google 11y ago Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows re…
CVE-2015-1322 medium 4.6 FIX debian debianubuntu ubuntu ubuntu 11y ago Directory traversal vulnerability in the Ubuntu network-manager package for Ubuntu (vivid) before 0.9.10.0-4ubuntu15.1, Ubuntu 14.10 before 0.9.8.8-0ubuntu28.1, and Ubuntu 14.04 LTS before 0.9.8.8-0u…
CVE-2015-1321 medium 6.8 ubuntu ubuntu oxide_project 11y ago Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webp…
CVE-2015-1863 medium 5.8 FIX slesubuntu ubuntudebian debian w1.fi 11y ago Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information…
CVE-2015-1774 medium 6.8 FIX debian debianubuntu ubuntu rhel apachelibreoffice 11y ago The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code vi…
CVE-2015-3416 high 7.5 FIX slesubuntu ubuntudebian debian sqlitephp 11y ago The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to caus…
CVE-2015-3415 high 7.5 FIX slesubuntu ubuntudebian debian sqlitephp 11y ago The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free ope…
CVE-2015-3414 high 7.5 FIX slesubuntu ubuntudebian debian sqlitephp 11y ago SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and appli…
CVE-2015-3310 medium 4.3 FIX ubuntu ubuntudebian debian point-to-point_protocol_project 11y ago Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial…
CVE-2015-3148 medium 5.0 FIX debian debianubuntu ubuntususe suse haxxhp 11y ago cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
CVE-2015-3145 high 7.5 FIX debian debianubuntu ubuntususe suse haxxhp 11y ago The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and c…
CVE-2015-3143 medium 5.0 FIX debian debianubuntu ubuntumacos macos haxxhp 11y ago cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0…
CVE-2015-3333 high 7.5 ubuntu ubuntudebian debian google 11y ago Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknow…
CVE-2015-1249 high 7.5 ubuntu ubuntudebian debian google 11y ago Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1244 medium 5.0 ubuntu ubuntudebian debian google 11y ago The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which…
CVE-2015-1242 high 7.5 ubuntu ubuntudebian debian google 11y ago The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of ser…
CVE-2015-1241 medium 4.3 ubuntu ubuntudebian debian rhel google 11y ago Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintend…
CVE-2015-1240 medium 5.0 ubuntu ubuntudebian debian google 11y ago gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL p…
CVE-2015-1238 high 7.5 ubuntu ubuntudebian debian google 11y ago Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
CVE-2015-1237 high 7.5 ubuntu ubuntudebian debian google 11y ago Use-after-free vulnerability in the RenderFrameImpl::OnMessageReceived function in content/renderer/render_frame_impl.cc in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial…
CVE-2015-1236 medium 4.3 ubuntu ubuntudebian debian google 11y ago The MediaElementAudioSourceNode::process function in modules/webaudio/MediaElementAudioSourceNode.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 42.0.2311.90, allow…
CVE-2015-1235 medium 5.0 ubuntu ubuntudebian debian google 11y ago The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to bypass the Same Origi…
CVE-2015-1856 medium 5.5 FIX ubuntu ubuntudebian debian openstack 11y ago OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-vers…
CVE-2015-1852 medium 4.3 FIX ubuntu ubuntudebian debian openstack 11y ago The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configurat…
CVE-2015-2573 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
CVE-2015-2571 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
CVE-2015-2568 medium 5.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileg…
CVE-2015-0505 low 3.5 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
CVE-2015-0501 medium 5.7 ubuntu ubuntudebian debian rhel juniperoraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.
CVE-2015-0499 low 3.5 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Federated.
CVE-2015-0441 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Security …
CVE-2015-0433 medium 4.0 ubuntu ubuntudebian debian rhel oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
CVE-2013-7439 high 7.5 FIX debian debianubuntu ubuntu x.org 11y ago Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted r…
CVE-2015-1819 medium 5.0 FIX debian debian rhelubuntu ubuntu xmlsoft 11y ago Nokogiri vulnerable to libxml XML Entity Expansion
CVE-2015-2775 high 7.6 slesubuntu ubuntudebian debian gnu 11y ago Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
CVE-2015-0840 medium 4.3 FIX debian debianubuntu ubuntu debian 11y ago The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).
CVE-2015-1317 high 7.5 ubuntu ubuntu oxide_project 11y ago Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents w…
CVE-2015-1473 medium 6.4 FIX debian debianubuntu ubuntu gnu 11y ago The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca functi…
CVE-2015-1472 high 7.5 FIX debian debianubuntu ubuntu gnu 11y ago The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attac…
CVE-2015-0799 medium 4.3 suse suseubuntu ubuntu mozilla 11y ago The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying tha…
CVE-2015-1465 high 7.8 FIX debian debianubuntu ubuntu linux-kernel 11y ago The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period for redirecting lookups in the absence of caching, which all…
CVE-2015-2756 medium 4.9 FIX ubuntu ubuntudebian debianfedora fedora 11y ago QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and …
CVE-2015-0812 medium 4.3 suse suseubuntu ubuntu mozilla 11y ago Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement …
CVE-2015-0811 medium 6.4 suse suseubuntu ubuntu mozilla 11y ago The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image …
CVE-2015-0808 medium 5.0 suse suseubuntu ubuntu mozilla 11y ago The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which m…
CVE-2015-0806 high 7.5 suse suseubuntu ubuntu mozilla 11y ago The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferT…
CVE-2015-0805 high 7.5 suse suseubuntu ubuntu mozilla 11y ago The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurfac…
CVE-2015-0804 high 7.5 suse suseubuntu ubuntu mozilla 11y ago The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which all…
CVE-2015-0803 high 7.5 suse suseubuntu ubuntu mozilla 11y ago The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, w…
CVE-2015-0802 medium 6.0 EXP suse suseubuntu ubuntu mozilla 11y ago Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScr…
CVE-2015-2808 low 3.7 3.7 FIX slesdebian debian rhel oracleredhatsuse 11y ago The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to cond…
CVE-2015-2305 medium 6.8 FIX debian debiansuse suseubuntu ubuntu rxspencer_projectphp 11y ago Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow …
CVE-2015-2301 high 7.5 suse suseubuntu ubuntudebian debian php 11y ago Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have uns…
CVE-2014-9709 medium 5.0 FIX debian debiansuse suseubuntu ubuntu phplibgd 11y ago The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and applicati…
CVE-2014-8121 medium 5.0 FIX debian debiansuse suseubuntu ubuntu gnu 11y ago DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to …
CVE-2015-2316 medium 5.0 FIX fedora fedoraubuntu ubuntususe suse djangoproject 11y ago The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of servi…
CVE-2015-2265 high 7.5 FIX debian debianubuntu ubuntu linuxfoundation 11y ago The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (…
CVE-2015-0250 medium 6.4 FIX slesdebian debianubuntu ubuntu apacheredhat 11y ago Improper Input Validation in Apache Batik
CVE-2015-1804 high 8.5 FIX debian debianubuntu ubuntu x 11y ago The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows remote authenticate…
CVE-2015-1803 high 8.5 FIX debian debianubuntu ubuntu x 11y ago The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated u…
CVE-2015-1802 high 8.5 FIX debian debianubuntu ubuntu x 11y ago The bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 allows remote authenticated users to cause a denial of service (out-of-bounds write and crash)…
CVE-2015-2296 medium 6.8 FIX slesubuntu ubuntudebian debian python 11y ago The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
CVE-2014-8159 medium 6.9 FIX debian debian linux-kernelubuntu ubuntu 11y ago The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regi…
CVE-2015-2304 medium 6.4 FIX debian debianubuntu ubuntususe suse libarchive 11y ago Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
CVE-2015-0254 high 7.5 slesubuntu ubuntu apache 11y ago XXE in Apache Standard Taglibs
CVE-2015-2238 high 7.5 ubuntu ubuntu google 11y ago Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of service or possibly have other impact via unknown…
CVE-2015-1231 high 7.5 rhelubuntu ubuntu google 11y ago Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2015-1230 high 7.5 ubuntu ubuntu google 11y ago The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote a…
CVE-2015-1229 medium 5.0 rhelubuntu ubuntu google 11y ago net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allo…
CVE-2015-1228 high 7.5 rhelubuntu ubuntu google 11y ago The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not ini…
CVE-2015-1220 medium 6.8 ubuntu ubuntu google 11y ago Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attacker…
CVE-2015-1219 high 7.5 ubuntu ubuntu google 11y ago Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service…
CVE-2015-1218 high 7.5 ubuntu ubuntu google 11y ago Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecif…
CVE-2015-1217 high 7.5 ubuntu ubuntu google 11y ago The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compil…
CVE-2015-1216 high 7.5 ubuntu ubuntu google 11y ago Use-after-free vulnerability in the V8Window::namedPropertyGetterCustom function in bindings/core/v8/custom/V8WindowCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.7…
CVE-2015-1215 high 7.5 ubuntu ubuntu google 11y ago The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigg…
CVE-2015-1214 high 7.5 ubuntu ubuntu google 11y ago Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to caus…
CVE-2015-0228 medium 5.0 FIX debian debianubuntu ubuntususe suse apache 11y ago The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a…
CVE-2014-9683 low 3.6 FIX debian debianubuntu ubuntu linux-kernel 11y ago Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buf…