Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 3.6

    LOW
    CVE-2015-5273

    The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users to write to arbitrary files via a symlink attack on unpacked.cpio in a pre-created directory with a predictable name in /va... Read more

    • EPSS Score: %0.33
    • Published: Dec. 07, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-3196

    ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race ... Read more

    • EPSS Score: %5.68
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2015-3195

    The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain ... Read more

    • EPSS Score: %2.22
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-3194

    crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parame... Read more

    • EPSS Score: %64.37
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-3193

    The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for remote... Read more

    Affected Products : ubuntu_linux openssl node.js
    • EPSS Score: %23.41
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-1794

    The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segmentation fault) via a zero p value in an anonymous Diffie-Hellman (DH) ServerKeyExchange message.... Read more

    Affected Products : openssl
    • EPSS Score: %3.13
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-8480

    The VideoFramePool::PoolImpl::CreateFrame function in media/base/video_frame_pool.cc in Google Chrome before 47.0.2526.73 does not initialize memory for a video-frame data structure, which might allow remote attackers to cause a denial of service (out-of-... Read more

    Affected Products : chrome
    • EPSS Score: %0.79
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-8479

    Use-after-free vulnerability in the AudioOutputDevice::OnDeviceAuthorized function in media/audio/audio_output_device.cc in Google Chrome before 47.0.2526.73 allows attackers to cause a denial of service (heap memory corruption) or possibly have unspecifi... Read more

    Affected Products : chrome
    • EPSS Score: %0.14
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-8478

    Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.73, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more

    Affected Products : chrome v8
    • EPSS Score: %0.11
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6787

    Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %48.36
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-6786

    The CSPSourceList::matches function in WebKit/Source/core/frame/csp/CSPSourceList.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts a blob:, data:, or filesystem: URL as a match for a * pattern, which all... Read more

    Affected Products : chrome
    • EPSS Score: %0.77
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-6785

    The CSPSource::hostMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts an x.y hostname as a match for a *.x.y pattern, which might allow remote att... Read more

    Affected Products : chrome
    • EPSS Score: %0.77
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-6784

    The page serializer in Google Chrome before 47.0.2526.73 mishandles Mark of the Web (MOTW) comments for URLs containing a "--" sequence, which might allow remote attackers to inject HTML via a crafted URL, as demonstrated by an initial http://example.com?... Read more

    Affected Products : chrome
    • EPSS Score: %0.73
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-6783

    The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a signatu... Read more

    Affected Products : android chrome
    • EPSS Score: %0.25
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-6782

    The Document::open function in WebKit/Source/core/dom/Document.cpp in Google Chrome before 47.0.2526.73 does not ensure that page-dismissal event handling is compatible with modal-dialog blocking, which makes it easier for remote attackers to spoof Omnibo... Read more

    Affected Products : chrome
    • EPSS Score: %0.78
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-6781

    Integer overflow in the FontData::Bound function in data/font_data.cc in Google sfntly, as used in Google Chrome before 47.0.2526.73, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted offset or le... Read more

    Affected Products : chrome
    • EPSS Score: %1.72
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-6780

    Use-after-free vulnerability in the Infobars implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site, related to browser/ui/views/website_set... Read more

    Affected Products : chrome
    • EPSS Score: %1.16
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-6779

    PDFium, as used in Google Chrome before 47.0.2526.73, does not properly restrict use of chrome: URLs, which allows remote attackers to bypass intended scheme restrictions via a crafted PDF document, as demonstrated by a document with a link to a chrome://... Read more

    Affected Products : chrome
    • EPSS Score: %0.60
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-6778

    The CJBig2_SymbolDict class in fxcodec/jbig2/JBig2_SymbolDict.cpp in PDFium, as used in Google Chrome before 47.0.2526.73, allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via a P... Read more

    Affected Products : chrome
    • EPSS Score: %1.34
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-6777

    Use-after-free vulnerability in the ContainerNode::notifyNodeInsertedInternal function in WebKit/Source/core/dom/ContainerNode.cpp in the DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possi... Read more

    Affected Products : chrome
    • EPSS Score: %1.58
    • Published: Dec. 06, 2015
    • Modified: Apr. 12, 2025
Showing 20 of 291551 Results