Show filters
352 Total Results
Displaying 111-120 of 352
Sort by:
Attacker Value
Unknown

CVE-2015-2808

Disclosure Date: April 01, 2015 (last updated October 05, 2023)
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
0
Attacker Value
Unknown

CVE-2014-8169

Disclosure Date: March 18, 2015 (last updated October 05, 2023)
automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environment variable values instead of the values for the user used to run the mapped program, which allows local users to gain privileges via a Trojan horse program in the user home directory.
0
Attacker Value
Unknown

CVE-2015-0228

Disclosure Date: March 08, 2015 (last updated October 05, 2023)
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.
0
Attacker Value
Unknown

CVE-2015-0832

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.
0
Attacker Value
Unknown

CVE-2015-0825

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory allocation during playback.
0
Attacker Value
Unknown

CVE-2015-0829

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
0
Attacker Value
Unknown

CVE-2015-0819

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.
0
Attacker Value
Unknown

CVE-2015-0834

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.
0
Attacker Value
Unknown

CVE-2015-0830

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation log, which allows remote attackers to cause a denial of service (application crash) via crafted WebGL content.
0
Attacker Value
Unknown

CVE-2015-0821

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions.
0