Show filters
116 Total Results
Displaying 11-20 of 116
Sort by:
Attacker Value
Unknown

CVE-2015-0834

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.
0
Attacker Value
Unknown

CVE-2015-0830

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation log, which allows remote attackers to cause a denial of service (application crash) via crafted WebGL content.
0
Attacker Value
Unknown

CVE-2015-0821

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions.
0
Attacker Value
Unknown

CVE-2015-0824

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of service (out-of-bounds write of zero values, and application crash) via vectors that trigger use of DrawTarget and the Cairo library for image drawing.
0
Attacker Value
Unknown

CVE-2015-0820

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbox protection mechanism via a crafted web site.
0
Attacker Value
Unknown

CVE-2015-0826

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read of heap memory) via a crafted Cascading Style Sheets (CSS) token sequence that triggers a restyle or reflow operation.
0
Attacker Value
Unknown

CVE-2015-0823

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic Developer Console information or possibly have unspecified other impact by leveraging incorrect macro expansion, related to the ots::ots_gasp_parse function.
0
Attacker Value
Unknown

CVE-2014-8564

Disclosure Date: November 13, 2014 (last updated October 05, 2023)
The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) Elliptic Curve Cryptography (ECC) certificate or (2) certificate signing requests (CSR), related to generating key IDs.
0
Attacker Value
Unknown

CVE-2014-3615

Disclosure Date: November 01, 2014 (last updated October 05, 2023)
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
0
Attacker Value
Unknown

CVE-2014-7155

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges via vectors involving an (1) HLT, (2) LGDT, (3) LIDT, or (4) LMSW instruction.
0