Show filters
104 Total Results
Displaying 31-40 of 104
Sort by:
Attacker Value
Unknown

CVE-2017-9406

Disclosure Date: June 02, 2017 (last updated November 26, 2024)
In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file.
0
Attacker Value
Unknown

CVE-2017-9408

Disclosure Date: June 02, 2017 (last updated November 26, 2024)
In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.
0
Attacker Value
Unknown

CVE-2015-2157

Disclosure Date: March 27, 2015 (last updated October 05, 2023)
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.
0
Attacker Value
Unknown

CVE-2015-0832

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.
0
Attacker Value
Unknown

CVE-2015-0825

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory allocation during playback.
0
Attacker Value
Unknown

CVE-2015-0829

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
0
Attacker Value
Unknown

CVE-2015-0819

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.
0
Attacker Value
Unknown

CVE-2015-0834

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.
0
Attacker Value
Unknown

CVE-2015-0830

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation log, which allows remote attackers to cause a denial of service (application crash) via crafted WebGL content.
0
Attacker Value
Unknown

CVE-2015-0824

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of service (out-of-bounds write of zero values, and application crash) via vectors that trigger use of DrawTarget and the Cairo library for image drawing.
0