Oracle
oracle
11,395 CVEs • 1,102 products
Products (1,102)
Click to collapseToggle
Products (1,102)
Click to collapse
CVEs (11,395)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538. |
4Canonical MozillaOpensuse+1 more4Firefox OpensuseSolaris+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an i...Show more |
4Canonical MozillaOpensuse+1 more4Firefox OpensuseSolaris+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a SharedWorker object tha...Show more |
5Canonical FedoraprojectGnome+2 more5Fedora Gdk PixbufOpensuse+2 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other produ...Show more |
4Canonical MozillaOpensuse+1 more4Firefox OpensuseSolaris+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wil...Show more |
4Canonical MozillaOpensuse+1 more5Firefox Firefox OsOpensuse+2 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified o...Show more |
4Canonical MozillaOpensuse+1 more5Firefox Firefox OsOpensuse+2 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 allows remote attackers to have an unspecified impact by leveraging a...Show more |
4Canonical MozillaOpensuse+1 more5Firefox Firefox OsOpensuse+2 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly hav...Show more |
4Canonical MozillaOpensuse+1 more4Firefox OpensuseSolaris+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via malformed...Show more |
4Canonical MozillaOpensuse+1 more4Firefox OpensuseSolaris+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via malformed WebM video data. |
4Canonical MozillaOpensuse+1 more4Firefox OpensuseSolaris+1 moreMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash...Show more |
3Mozilla OpensuseOracle3Firefox OpensuseSolarisMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request. |
3Mozilla OpensuseOracle3Firefox OpensuseSolarisMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 4.6 MEDIUM· v2 mar_read.c in the Updater in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows local users to gain privileges or cause a denial of service (out-of-bounds write) via a crafted name of a Mozilla Archive (...Show more |
3Mozilla OpensuseOracle3Firefox OpensuseSolarisMay 6, 2026 Aug 16, 2015 N/A· v4 N/A· v3 3.3 LOW· v2 Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors inv...Show more |
8Apple CanonicalDebian+5 more12Debian Linux Enterprise LinuxFedora+9 moreMay 6, 2026 Aug 14, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack. |
2Apache Oracle3Activemq Business Intelligence PublisherFusion MiddlewareMay 6, 2026 Aug 14, 2015 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command. |
2Apache Oracle6Groovy Health Sciences Clinical Development CenterRetail Order Broker Cloud Service+3 moreMay 6, 2026 Aug 13, 2015 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object. |
7Arista DebianFedoraproject+4 more24Debian Linux Enterprise Linux Compute Node EusEnterprise Linux Desktop+21 moreMay 6, 2026 Aug 12, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors. |
6Canonical MozillaOpensuse+3 more15Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+12 moreApr 22, 2026 Aug 8, 2015 N/A· v4 8.8 HIGH· v3 4.3 MEDIUM· v2 The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vector...Show more |
8Canonical DebianGoogle+5 more13Chrome Debian LinuxLeap+10 moreMay 6, 2026 Jul 23, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer ove...Show more |