Show filters
322 Total Results
Displaying 31-40 of 322
Sort by:
Attacker Value
Unknown

CVE-2013-3718

Disclosure Date: November 01, 2019 (last updated November 27, 2024)
evince is missing a check on number of pages which can lead to a segmentation fault
Attacker Value
Unknown

CVE-2016-6306

Disclosure Date: September 26, 2016 (last updated November 08, 2023)
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
Attacker Value
Unknown

CVE-2016-0610

Disclosure Date: January 21, 2016 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
0
Attacker Value
Unknown

CVE-2015-2305

Disclosure Date: March 30, 2015 (last updated October 05, 2023)
Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary code via a large regular expression that leads to a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2015-2301

Disclosure Date: March 30, 2015 (last updated October 05, 2023)
Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted renaming of a Phar archive to the name of an existing file.
0
Attacker Value
Unknown

CVE-2015-2317

Disclosure Date: March 25, 2015 (last updated October 05, 2023)
The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.
0
Attacker Value
Unknown

CVE-2015-2316

Disclosure Date: March 25, 2015 (last updated October 05, 2023)
The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.
0
Attacker Value
Unknown

CVE-2015-0228

Disclosure Date: March 08, 2015 (last updated October 05, 2023)
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.
0
Attacker Value
Unknown

CVE-2015-0832

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.
0
Attacker Value
Unknown

CVE-2015-0825

Disclosure Date: February 25, 2015 (last updated October 05, 2023)
Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory allocation during playback.
0