Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-7174 | 1 Mozilla | 2 Firefox, Firefox Esr | 2016-12-21 | 7.5 HIGH | N/A |
The nsAttrAndChildArray::GrowBy function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors, related to an "overflow." | |||||
CVE-2015-7175 | 1 Mozilla | 2 Firefox, Firefox Esr | 2016-12-21 | 7.5 HIGH | N/A |
The XULContentSinkImpl::AddText function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors, related to an "overflow." | |||||
CVE-2015-7176 | 1 Mozilla | 2 Firefox, Firefox Esr | 2016-12-21 | 7.5 HIGH | N/A |
The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via unknown vectors. | |||||
CVE-2015-7177 | 1 Mozilla | 2 Firefox, Firefox Esr | 2016-12-21 | 7.5 HIGH | N/A |
The InitTextures function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors. | |||||
CVE-2015-7178 | 2 Microsoft, Mozilla | 3 Windows, Firefox, Firefox Esr | 2016-12-21 | 7.5 HIGH | N/A |
The ProgramBinary::linkAttributes function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows, mishandles shader access, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted (1) OpenGL or (2) WebGL content. | |||||
CVE-2015-7179 | 2 Microsoft, Mozilla | 3 Windows, Firefox, Firefox Esr | 2016-12-21 | 7.5 HIGH | N/A |
The VertexBufferInterface::reserveVertexSpace function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows, incorrectly allocates memory for shader attribute arrays, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via crafted (1) OpenGL or (2) WebGL content. | |||||
CVE-2015-7180 | 1 Mozilla | 2 Firefox, Firefox Esr | 2016-12-21 | 7.5 HIGH | N/A |
The ReadbackResultWriterD3D11::Run function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 misinterprets the return value of a function call, which might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors. | |||||
CVE-2015-7235 | 1 Cp Reservation Calender Project | 1 Cp Reservation Calender | 2016-12-21 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a dex_reservations_calendar_load2 action or (2) dex_item parameter in a dex_reservations_check_posted_data action in a request to the default URI. | |||||
CVE-2015-7327 | 1 Mozilla | 1 Firefox | 2016-12-21 | 4.3 MEDIUM | N/A |
Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that makes performance.now calls. | |||||
CVE-2016-3129 | 1 Blackberry | 1 Good Enterprise Mobility Server | 2016-12-21 | 8.5 HIGH | 6.6 MEDIUM |
A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in GEMS versions 2.1.5.3 to 2.2.22.25 allows remote attackers to obtain local administrator rights on the GEMS server via commands executed on the Karaf command shell. | |||||
CVE-2016-6656 | 1 Pivotal Software | 1 Greenplum | 2016-12-21 | 6.5 MEDIUM | 7.2 HIGH |
An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation of external tables using GPHDFS protocol has a vulnerability whereby arbitrary commands can be injected into the system. In order to exploit this vulnerability the user must have superuser 'gpadmin' access to the system or have been granted GPHDFS protocol permissions in order to create a GPHDFS external table. | |||||
CVE-2016-7882 | 1 Adobe | 1 Experience Manager | 2016-12-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Adobe Experience Manager versions 6.2 and earlier have an input validation issue in the WCMDebug filter that could be used in cross-site scripting attacks. | |||||
CVE-2016-7883 | 1 Adobe | 1 Experience Manager | 2016-12-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Adobe Experience Manager version 6.2 has an input validation issue in create Launch wizard that could be used in cross-site scripting attacks. | |||||
CVE-2016-7884 | 1 Adobe | 1 Experience Manager | 2016-12-21 | 4.3 MEDIUM | 6.1 MEDIUM |
Adobe Experience Manager versions 6.1 and earlier have an input validation issue in the DAM create assets that could be used in cross-site scripting attacks. | |||||
CVE-2016-7885 | 1 Adobe | 1 Experience Manager | 2016-12-21 | 6.8 MEDIUM | 8.8 HIGH |
Adobe Experience Manager versions 6.2 and earlier have a vulnerability that could be used in Cross-Site Request Forgery attacks. | |||||
CVE-2016-7888 | 1 Adobe | 1 Digital Editions | 2016-12-21 | 5.0 MEDIUM | 5.3 MEDIUM |
Adobe Digital Editions versions 4.5.2 and earlier has an important vulnerability that could lead to memory address leak. | |||||
CVE-2016-7959 | 1 Siemens | 1 Simatic Step 7 | 2016-12-21 | 1.9 LOW | 4.7 MEDIUM |
Siemens SIMATIC STEP 7 (TIA Portal) before 14 improperly stores pre-shared key data in TIA project files, which makes it easier for local users to obtain sensitive information by leveraging access to a file and conducting a brute-force attack. | |||||
CVE-2013-2212 | 1 Xen | 1 Xen | 2016-12-21 | 5.7 MEDIUM | N/A |
The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause a denial of service (CPU consumption and possibly hypervisor or guest kernel panic) via a crafted GFN range. | |||||
CVE-2013-4479 | 1 Supmua | 1 Sup | 2016-12-21 | 6.8 MEDIUM | N/A |
lib/sup/message_chunks.rb in Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the content_type of an email attachment. | |||||
CVE-2013-6487 | 1 Pidgin | 1 Pidgin | 2016-12-21 | 7.5 HIGH | N/A |
Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a large Content-Length value, which triggers a buffer overflow. |