|
271561
|
- |
|
devexpress
|
ajax_control_toolkit
|
Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (d…
|
CWE-22
Path Traversal
|
CVE-2015-4670
|
2024-11-21 11:31 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271562
|
- |
|
pimcore
|
pimcore
|
SQL injection vulnerability in pimcore before build 3473 allows remote attackers to execute arbitrary SQL commands via the filter parameter to admin/asset/grid-proxy.
|
CWE-89
SQL Injection
|
CVE-2015-4426
|
2024-11-21 11:31 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271563
|
- |
|
pimcore
|
pimcore
|
Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permission to create or write to arbitrary files via a .. (dot dot) in the dir param…
|
CWE-22
Path Traversal
|
CVE-2015-4425
|
2024-11-21 11:31 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271564
|
- |
|
oracle mozilla
|
solaris firefox
|
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CV…
|
CWE-189
Numeric Errors
|
CVE-2015-4496
|
2024-11-21 11:31 |
2015-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271565
|
- |
|
oracle mozilla canonical opensuse
|
solaris firefox ubuntu_linux opensuse
|
Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute ar…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-4493
|
2024-11-21 11:31 |
2015-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271566
|
- |
|
oracle mozilla canonical opensuse
|
solaris firefox ubuntu_linux opensuse
|
Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a Sh…
|
NVD-CWE-Other
|
CVE-2015-4492
|
2024-11-21 11:31 |
2015-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271567
|
- |
|
gnome oracle fedoraproject canonical opensuse
|
gdk-pixbuf solaris fedora ubuntu_linux opensuse
|
Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on L…
|
CWE-189
Numeric Errors
|
CVE-2015-4491
|
2024-11-21 11:31 |
2015-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271568
|
- |
|
mozilla canonical opensuse oracle
|
firefox ubuntu_linux opensuse solaris
|
The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem U…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4490
|
2024-11-21 11:31 |
2015-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271569
|
- |
|
oracle mozilla canonical opensuse
|
solaris firefox firefox_os ubuntu_linux opensuse
|
The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possib…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-4489
|
2024-11-21 11:31 |
2015-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271570
|
- |
|
oracle canonical opensuse mozilla
|
solaris ubuntu_linux opensuse firefox_os firefox
|
Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 allows remote attackers to have an unspecified im…
|
NVD-CWE-Other
|
CVE-2015-4488
|
2024-11-21 11:31 |
2015-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|