Show filters
171 Total Results
Displaying 51-60 of 171
Sort by:
Attacker Value
Unknown

CVE-2015-4485

Disclosure Date: August 16, 2015 (last updated October 23, 2024)
Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via malformed WebM video data.
0
Attacker Value
Unknown

CVE-2015-4490

Disclosure Date: August 16, 2015 (last updated October 05, 2023)
The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.
0
Attacker Value
Unknown

CVE-2015-4483

Disclosure Date: August 16, 2015 (last updated October 05, 2023)
Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request.
0
Attacker Value
Unknown

CVE-2015-4481

Disclosure Date: August 16, 2015 (last updated October 23, 2024)
Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during an update.
0
Attacker Value
Unknown

CVE-2015-4493

Disclosure Date: August 16, 2015 (last updated October 23, 2024)
Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an invalid size field in an esds chunk in MPEG-4 video data, a related issue to CVE-2015-1539.
0
Attacker Value
Unknown

CVE-2015-1819

Disclosure Date: August 14, 2015 (last updated October 05, 2023)
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
0
Attacker Value
Unknown

CVE-2015-1270

Disclosure Date: July 23, 2015 (last updated October 05, 2023)
The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file.
0
Attacker Value
Unknown

CVE-2015-1283

Disclosure Date: July 23, 2015 (last updated October 05, 2023)
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.
0
Attacker Value
Unknown

CVE-2015-2648

Disclosure Date: July 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to DML.
0
Attacker Value
Unknown

CVE-2015-4752

Disclosure Date: July 16, 2015 (last updated October 05, 2023)
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to Server : I_S.
0