Total
165 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-7196 | 1 Mozilla | 2 Firefox, Firefox Esr | 2016-12-07 | 6.8 MEDIUM | N/A |
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, when a Java plugin is enabled, allow remote attackers to cause a denial of service (incorrect garbage collection and application crash) or possibly execute arbitrary code via a crafted Java applet that deallocates an in-use JavaScript wrapper. | |||||
CVE-2015-7192 | 2 Apple, Mozilla | 2 Mac Os X, Firefox | 2016-12-07 | 7.5 HIGH | N/A |
The accessibility-tools feature in Mozilla Firefox before 42.0 on OS X improperly interacts with the implementation of the TABLE element, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using an NSAccessibilityIndexAttribute value to reference a row index. | |||||
CVE-2015-7200 | 1 Mozilla | 2 Firefox, Firefox Esr | 2016-12-07 | 7.5 HIGH | N/A |
The CryptoKey interface implementation in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 lacks status checking, which allows attackers to have an unspecified impact via vectors related to a cryptographic key. | |||||
CVE-2015-6736 | 1 Quiz Project | 1 Quiz | 2016-12-07 | 5.0 MEDIUM | N/A |
The Quiz extension for MediaWiki allows remote attackers to cause a denial of service via regex metacharacters in a regular expression. | |||||
CVE-2015-6735 | 1 Timedmediahandler Project | 1 Timedmediahandler | 2016-12-07 | 5.0 MEDIUM | N/A |
The reset functionality in the TimedMediaHandler extension for MediaWiki does not create a new transcode, which allows remote attackers to cause a denial of service (transcode deletion) by resetting a transcode. | |||||
CVE-2015-4963 | 1 Ibm | 1 Security Access Manager For Web | 2016-12-07 | 7.5 HIGH | N/A |
IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via unspecified vectors. | |||||
CVE-2015-4941 | 1 Ibm | 1 Websphere Mq Light | 2016-12-07 | 5.0 MEDIUM | 5.3 MEDIUM |
IBM WebSphere MQ Light 1.x before 1.0.2 mishandles abbreviated TLS handshakes, which allows remote attackers to cause a denial of service (MQXR service crash) via unspecified vectors. | |||||
CVE-2015-4943 | 1 Ibm | 1 Websphere Mq Light | 2016-12-07 | 5.0 MEDIUM | 5.3 MEDIUM |
IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconnect actions, a different vulnerability than CVE-2015-4942. | |||||
CVE-2015-1463 | 2 Clamav, Fedoraproject | 2 Clamav, Fedora | 2016-12-07 | 5.0 MEDIUM | N/A |
ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization." | |||||
CVE-2016-1640 | 1 Google | 1 Chrome | 2016-12-02 | 4.3 MEDIUM | 4.3 MEDIUM |
The Web Store inline-installer implementation in the Extensions UI in Google Chrome before 49.0.2623.75 does not block installations upon deletion of an installation frame, which makes it easier for remote attackers to trick a user into believing that an installation request originated from the user's next navigation target via a crafted web site. | |||||
CVE-2015-3292 | 1 Netapp | 1 Oncommand Workflow Automation | 2016-12-02 | 10.0 HIGH | N/A |
The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2015-3002 | 1 Juniper | 13 Junos, Srx100, Srx110 and 10 more | 2016-12-02 | 6.9 MEDIUM | N/A |
Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, and 12.3X48 before 12.3X48-D10 on SRX series devices does not properly enforce the log-out-on-disconnect feature when configured in the [system port console] stanza, which allows physically proximate attackers to reconnect to the console port and gain administrative access by leveraging access to the device. | |||||
CVE-2015-7410 | 1 Ibm | 1 Sterling B2b Integrator | 2016-11-28 | 5.8 MEDIUM | 7.4 HIGH |
The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors. | |||||
CVE-2015-5229 | 1 Redhat | 8 Enterprise Linux, Enterprise Linux Desktop, Enterprise Linux Hpc Node and 5 more | 2016-11-28 | 5.0 MEDIUM | 7.5 HIGH |
The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors. | |||||
CVE-2015-1157 | 1 Apple | 3 Iphone Os, Itunes, Mac Os X | 2016-11-28 | 7.8 HIGH | N/A |
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message. | |||||
CVE-2013-7424 | 1 Gnu | 1 Glibc | 2016-11-28 | 5.1 MEDIUM | N/A |
The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6. | |||||
CVE-2005-0138 | 1 Sgi | 1 Irix | 2016-05-09 | 7.5 HIGH | N/A |
rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined. NOTE: while this issue occurs in a security mechanism, there is no apparent attacker role and probably does not satisfy the CVE definition of a vulnerability. | |||||
CVE-2015-1150 | 1 Apple | 1 Os X Server | 2016-03-31 | 5.0 MEDIUM | N/A |
The Firewall component in Apple OS X Server before 4.1 uses an incorrect pathname in configuration files, which allows remote attackers to bypass network-access restrictions by sending packets for which custom-rule blocking was intended. | |||||
CVE-2016-2314 | 1 Huawei | 2 Mt882, Mt882 Firmware | 2016-03-22 | 6.3 MEDIUM | 4.9 MEDIUM |
GlobespanVirata ftpd 1.0, as used on Huawei SmartAX MT882 devices V200R002B022 Arg, allows remote authenticated users to cause a denial of service (device outage) by using the FTP MKD command to create a directory with a long name, and then using certain other commands. | |||||
CVE-2015-7793 | 1 Corega | 1 Cg-wlbaragm Firmware | 2015-12-30 | 5.0 MEDIUM | 5.8 MEDIUM |
Corega CG-WLBARAGM devices provide an open proxy service, which allows remote attackers to trigger outbound network traffic via unspecified vectors. |