LiveActive security incident?Get immediate response
CVE archive

May 2015

Browse CVE records published in May 2015, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 507 matching CVEs · Page 9 of 11.

Unknown · CVSS Not scored

CVE-2015-1252: common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, whic...

common/partial_circular_buffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, which allows remote attackers to bypass a sandbox protection mechanism or cause a denial of service (out-of-bounds write) via vectors that trigger a write operation with a large amount of data, related to the PartialCircularBuffer::Write and PartialCircularBuffer::DoWrite functions.

Published May 20, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1257: platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Chrome be...

platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, does not properly handle an insufficient number of values in an feColorMatrix filter, which allows remote attackers to cause a denial of service (container overflow) or possibly have unspecified other impact via a crafted document.

Published May 20, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1253: core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome befo...

core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that appends a child to a SCRIPT element, related to the insert and executeReparentTask functions.

Published May 20, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1258: Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit...

Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a size field, and consequently cause a denial of service or possibly have unspecified other impact, via a crafted frame size in VP9 video data.

Published May 20, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1255: Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio implemen...

Use-after-free vulnerability in content/renderer/media/webaudio_capturer_source.cc in the WebAudio implementation in Google Chrome before 43.0.2357.65 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by leveraging improper handling of a stop action for an audio track.

Published May 20, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1261: android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65...

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during construction of a page-info popup, which allows remote attackers to spoof the URL bar or deliver misleading popup content via crafted text.

Published May 20, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1243: Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp...

Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering an attempt to unregister a MutationObserver object that is not currently registered.

Published May 1, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1156: The page-loading implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x...

The page-loading implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, does not properly handle the rel attribute in an A element, which allows remote attackers to bypass the Same Origin Policy for a link's target, and spoof the user interface, via a crafted web site.

Published May 8, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1157: CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and mess...

CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.

Published May 28, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-0962: Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certi...

Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate's trust relationship.

Published May 25, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1006: A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions...

A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, OptoOPCServer versions prior to R9.4c, and OptoDataLink version R9.4d and prior versions that were installed by PAC Project installer, versions prior to R9.4006, is susceptible to a heap-based buffer overflow condition that may allow remote code execution on the target system. Opto 22 suggests upgrading to the new product version as soon as possible.

Published May 10, 2019 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-0797: GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbi...

GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.

Published May 14, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-0744: Cisco DTA Control System (DTACS) 4.0.0.9 and Cisco Headend System Release allow remote attackers to cause a...

Cisco DTA Control System (DTACS) 4.0.0.9 and Cisco Headend System Release allow remote attackers to cause a denial of service (CPU and memory consumption, and TCP service outage) via (1) a SYN flood or (2) another type of TCP traffic flood, aka Bug IDs CSCus50642, CSCus50662, CSCus50625, CSCus50657, and CSCus68315.

Published May 30, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-0742: The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9....

The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105), 9.3(2.100), 9.4(0.115), 100.13(0.21), 100.13(20.3), 100.13(21.9), and 100.14(1.1) does not properly implement multicast-forwarding registration, which allows remote attackers to cause a denial of service (forwarding outage) via a crafted multicast packet, aka Bug ID CSCus74398.

Published May 21, 2015 · Updated Aug 6, 2024