CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2015-4493

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an invalid size field in an esds chunk in MPEG-4 video data, a related issue to CVE-2015-1539.

    Published: 11 Aug 2015
    10
    Critical

    CVE-2015-4474

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 11 Aug 2015
    7.5
    High

    CVE-2015-4475

    Last Modified: 12 Apr 2025

    The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.

    Published: 11 Aug 2015
    10
    Critical

    CVE-2015-4477

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the MediaStream playback feature in Mozilla Firefox before 40.0 allows remote attackers to execute arbitrary code via unspecified use of the Web Audio API.

    Published: 11 Aug 2015
    5
    Medium

    CVE-2015-4478

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which allows remote attackers to bypass the Same Origin Policy via the reviver parameter to the JSON.parse method.

    Published: 11 Aug 2015
    4.3
    Medium

    CVE-2015-4483

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request.

    Published: 11 Aug 2015
    5
    Medium

    CVE-2015-4484

    Last Modified: 12 Apr 2025

    The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash) by leveraging the use of shared memory and accessing (1) an Atomics object or (2) a SharedArrayBuffer object.

    Published: 11 Aug 2015
    10
    Critical

    CVE-2015-4485

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via malformed WebM video data.

    Published: 11 Aug 2015
    7.5
    High

    CVE-2015-4488

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 allows remote attackers to have an unspecified impact by leveraging a StyleAnimationValue::operator self assignment.

    Published: 11 Aug 2015
    7.5
    High

    CVE-2015-4489

    Last Modified: 12 Apr 2025

    The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.

    Published: 11 Aug 2015
    4.3
    Medium

    CVE-2015-4490

    Last Modified: 12 Apr 2025

    The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.

    Published: 11 Aug 2015
    6.8
    Medium

    CVE-2015-4491

    Last Modified: 12 Apr 2025

    Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via crafted bitmap dimensions that are mishandled during scaling.

    Published: 11 Aug 2015
    4.3
    Medium

    CVE-2015-6241

    Last Modified: 12 Apr 2025

    The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree implementation in Wireshark 1.12.x before 1.12.7 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 11 Aug 2015
    4.3
    Medium

    CVE-2015-6242

    Last Modified: 12 Apr 2025

    The wmem_block_split_free_chunk function in epan/wmem/wmem_allocator_block.c in the wmem block allocator in the memory manager in Wireshark 1.12.x before 1.12.7 does not properly consider a certain case of multiple realloc operations that restore a memory chunk to its original size, which allows remote attackers to cause a denial of service (incorrect free operation and application crash) via a crafted packet.

    Published: 11 Aug 2015
    4.3
    Medium

    CVE-2015-6243

    Last Modified: 12 Apr 2025

    The dissector-table implementation in epan/packet.c in Wireshark 1.12.x before 1.12.7 mishandles table searches for empty strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the (1) dissector_get_string_handle and (2) dissector_get_default_string_handle functions.

    Published: 11 Aug 2015
    4.3
    Medium

    CVE-2015-6244

    Last Modified: 12 Apr 2025

    The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 11 Aug 2015
    4.3
    Medium

    CVE-2015-6246

    Last Modified: 12 Apr 2025

    The dissect_wa_payload function in epan/dissectors/packet-waveagent.c in the WaveAgent dissector in Wireshark 1.12.x before 1.12.7 mishandles large tag values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 11 Aug 2015
    4.3
    Medium

    CVE-2015-6247

    Last Modified: 12 Apr 2025

    The dissect_openflow_tablemod_v5 function in epan/dissectors/packet-openflow_v5.c in the OpenFlow dissector in Wireshark 1.12.x before 1.12.7 does not validate a certain offset value, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

    Published: 11 Aug 2015
    4.3
    Medium

    CVE-2015-6248

    Last Modified: 12 Apr 2025

    The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 11 Aug 2015
    4.3
    Medium

    CVE-2015-6249

    Last Modified: 12 Apr 2025

    The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.7 does not prevent the conflicting use of a table for both IPv4 and IPv6 addresses, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 11 Aug 2015
    7.2
    High

    CVE-2015-6565

    Last Modified: 12 Apr 2025

    sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruption) or possibly have unspecified other impact by writing to a device, as demonstrated by writing an escape sequence.

    Published: 11 Aug 2015
    2.1
    Low

    CVE-2015-6252

    Last Modified: 12 Apr 2025

    The vhost_dev_ioctl function in drivers/vhost/vhost.c in the Linux kernel before 4.1.5 allows local users to cause a denial of service (memory consumption) via a VHOST_SET_LOG_FD ioctl call that triggers permanent file-descriptor allocation.

    Published: 10 Aug 2015
    5.5
    Medium

    CVE-2015-5160

    Last Modified: 21 Nov 2024

    libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.

    Published: 10 Aug 2015
    6.5
    Medium

    CVE-2015-5187

    Last Modified: 20 Apr 2025

    Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.

    Published: 10 Aug 2015
    7.5
    High

    CVE-2015-8948

    Last Modified: 12 Apr 2025

    idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.

    Published: 10 Aug 2015
    5
    Medium

    CVE-2015-6251

    Last Modified: 12 Apr 2025

    Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.

    Published: 10 Aug 2015
    7
    High

    CVE-2015-9016

    Last Modified: 21 Nov 2024

    In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously freed by blk_mq_complete_request. This could lead to local escalation of privilege. Product: Android. Versions: Android kernel. Android ID: A-63083046.

    Published: 9 Aug 2015
    9.8
    Critical

    CVE-2015-6835

    Last Modified: 12 Apr 2025

    The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content.

    Published: 9 Aug 2015
    10
    Critical

    CVE-2015-2897

    Last Modified: 12 Apr 2025

    Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNET session.

    Published: 8 Aug 2015
    6.8
    Medium

    CVE-2015-2980

    Last Modified: 12 Apr 2025

    The Yodobashi application 1.2.1.0 and earlier for Android allows remote attackers to execute arbitrary Java methods, and consequently obtain sensitive information or execute OS commands, via a crafted HTML document.

    Published: 8 Aug 2015
    1.9
    Low

    CVE-2015-5960

    Last Modified: 12 Apr 2025

    Mozilla Firefox OS before 2.2 allows physically proximate attackers to bypass the pass-code protection mechanism and access USB Mass Storage (UMS) media volumes by using the USB interface for a mount operation.

    Published: 8 Aug 2015
    3.3
    Low

    CVE-2015-5961

    Last Modified: 12 Apr 2025

    The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to bypass intended access restrictions by spoofing that server.

    Published: 8 Aug 2015
    4.3
    Medium

    CVE-2015-2744

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Search app in Gaia in Mozilla Firefox OS before 2.2 allows remote attackers to inject arbitrary HTML via a crafted search link that is mishandled after re-opening the browser or opening the tab view.

    Published: 8 Aug 2015
    4.3
    Medium

    CVE-2015-2745

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Search app in Gaia in Mozilla Firefox OS before 2.2 allow remote attackers to inject arbitrary HTML via the (1) name or (2) title field in card content associated with a search link that is mishandled after a HOME button press or a Show Windows action, as demonstrated by embedding an arbitrary application or spoofing the account-creation page.

    Published: 8 Aug 2015
    4.3
    Medium

    CVE-2015-4494

    Last Modified: 12 Apr 2025

    Mozilla Firefox OS before 2.2 does not require the wifi-manage privilege for reading a Wi-Fi system message, which allows attackers to obtain potentially sensitive information via a crafted app.

    Published: 8 Aug 2015
    5
    Medium

    CVE-2015-5962

    Last Modified: 12 Apr 2025

    Integer signedness error in the SharedBufferManagerParent::RecvAllocateGrallocBuffer function in the buffer-management implementation in the graphics layer in Mozilla Firefox OS before 2.2 might allow attackers to cause a denial of service (memory corruption) via a negative value of a size parameter.

    Published: 8 Aug 2015
    9.3
    Critical

    CVE-2015-4674

    Last Modified: 12 Apr 2025

    The autoupdate implementation in TimeDoctor Pro 1.4.72.3 on Windows relies on unsigned installer files that are retrieved without use of SSL, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.

    Published: 7 Aug 2015
    7.8
    High

    CVE-2015-0568

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the msm_set_crop function in drivers/media/video/msm/msm_camera.c in the MSM-Camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (memory corruption) via an application that makes a crafted ioctl call.

    Published: 7 Aug 2015
    5
    Medium

    CVE-2015-6806

    Last Modified: 12 Apr 2025

    The MScrollV function in ansi.c in GNU screen 4.3.1 and earlier does not properly limit recursion, which allows remote attackers to cause a denial of service (stack consumption) via an escape sequence with a large repeat count value.

    Published: 7 Aug 2015
    7.5
    High

    CVE-2015-5180

    Last Modified: 20 Apr 2025

    res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).

    Published: 7 Aug 2015
    6.1
    Medium

    CVE-2015-5241

    Last Modified: 20 Apr 2025

    After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect the browser to an unintended web page in Apache jUDDI 3.1.2, 3.1.3, 3.1.4, and 3.1.5 when utilizing the portlets based user interface also known as 'Pluto', 'jUDDI Portal', 'UDDI Portal' or 'uddi-console'. User session data, credentials, and auth tokens are cleared before the redirect.

    Published: 7 Aug 2015
    8.8
    High

    CVE-2015-4495

    Last Modified: 22 Apr 2026

    The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

    Published: 6 Aug 2015
    7.5
    High

    CVE-2015-5177

    Last Modified: 20 Apr 2025

    Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.

    Published: 6 Aug 2015
    7.3
    High

    CVE-2015-6831

    Last Modified: 12 Apr 2025

    Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObject, (2) SplObjectStorage, and (3) SplDoublyLinkedList, which are mishandled during unserialization.

    Published: 6 Aug 2015
    7.3
    High

    CVE-2015-6832

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the SPL unserialize implementation in ext/spl/spl_array.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to execute arbitrary code via crafted serialized data that triggers misuse of an array field.

    Published: 6 Aug 2015
    7.5
    High

    CVE-2015-7236

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.

    Published: 6 Aug 2015
    6.5
    Medium

    CVE-2017-0369

    Last Modified: 21 Nov 2024

    Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.

    Published: 6 Aug 2015
    6.1
    Medium

    CVE-2015-5156

    Last Modified: 12 Apr 2025

    The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via a crafted sequence of fragmented packets.

    Published: 6 Aug 2015
    Unknown

    CVE-2015-5762

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 6 Aug 2015
    4.3
    Medium

    CVE-2015-3439

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript functions via the target parameter, as demonstrated by executing a certain click function, related to _init.as and _fireEvent.as.

    Published: 5 Aug 2015