Latest CVE Feed
-
4.3
MEDIUMCVE-2015-1347
Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.... Read more
Affected Products : osticket- EPSS Score: %0.22
- Published: Jan. 23, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-1200
Race condition in pxz 4.999.99 Beta 3 uses weak file permissions for the output file when compressing a file before changing the permission to match the original file, which allows local users to bypass the intended access restrictions.... Read more
Affected Products : pxz- EPSS Score: %0.04
- Published: Jan. 23, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1180
Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the pageId parameter to networktile/bullet.... Read more
Affected Products : eventsentry- EPSS Score: %0.22
- Published: Jan. 23, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1176
Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.... Read more
Affected Products : osticket- EPSS Score: %0.30
- Published: Jan. 23, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9640
oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.... Read more
- EPSS Score: %1.28
- Published: Jan. 23, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9639
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.... Read more
- EPSS Score: %1.36
- Published: Jan. 23, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9638
oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.... Read more
- EPSS Score: %1.28
- Published: Jan. 23, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-9623
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.... Read more
- EPSS Score: %1.01
- Published: Jan. 23, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-8802
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit a... Read more
- EPSS Score: %7.98
- Published: Jan. 23, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1346
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- EPSS Score: %0.31
- Published: Jan. 22, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1205
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- EPSS Score: %1.20
- Published: Jan. 22, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7948
The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_update_job.cc in Google Chrome before 40.0.2214.91 proceeds with AppCache caching for SSL sessions even if there is an X.509 certificate error, which allows... Read more
Affected Products : chrome- EPSS Score: %0.57
- Published: Jan. 22, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-7947
OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2.c, and tcd.c.... Read more
Affected Products : chrome- EPSS Score: %1.58
- Published: Jan. 22, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-7946
The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as used in Google Chrome before 40.0.2214.91, skips captions during table layout in certain situations, which allows remote attackers to cause a denial of ser... Read more
Affected Products : chrome- EPSS Score: %2.41
- Published: Jan. 22, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-7945
OpenJPEG before r2908, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, and t2.c.... Read more
Affected Products : chrome- EPSS Score: %1.68
- Published: Jan. 22, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-7944
The sycc422_to_rgb function in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 40.0.2214.91, does not properly handle odd values of image width, which allows remote attackers to cause a denial of service (out-of-bounds read) ... Read more
Affected Products : chrome- EPSS Score: %1.68
- Published: Jan. 22, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-7943
Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.... Read more
- EPSS Score: %1.71
- Published: Jan. 22, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-7942
The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.... Read more
- EPSS Score: %2.36
- Published: Jan. 22, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-7941
The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote attackers to cause a denial of service (ou... Read more
- EPSS Score: %2.25
- Published: Jan. 22, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-7940
The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN revision 293126, as used in Google Chrome before 40.0.2214.91, does not initialize memory for a data structure, which allows remote attackers to caus... Read more
- EPSS Score: %2.15
- Published: Jan. 22, 2015
- Modified: Apr. 12, 2025