Vulnerabilities > Canonical > Ubuntu Linux > High

DATE CVE VULNERABILITY TITLE RISK
2015-09-08 CVE-2015-5199 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in dlopen in libvdpau before 1.1.1 allows local users to gain privileges via the VDPAU_DRIVER environment variable.
local
low complexity
canonical libvdpau-project CWE-22
7.2
2015-09-08 CVE-2015-5198 Permissions, Privileges, and Access Controls vulnerability in multiple products
libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privileges via unspecified vectors, related to the VDPAU_DRIVER_PATH environment variable.
local
low complexity
libvdpau-project canonical CWE-264
7.2
2015-09-02 CVE-2015-3308 Denial of Service vulnerability in GnuTLS 'x509_ext.c' Use After Free
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
network
low complexity
gnu canonical
7.5
2015-08-16 CVE-2015-4492 Use After Free Memory Corruption vulnerability in Mozilla Firefox
Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a SharedWorker object that makes recursive calls to the open method of an XMLHttpRequest object.
network
low complexity
oracle mozilla canonical opensuse
7.5
2015-08-16 CVE-2015-4489 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.
network
low complexity
oracle mozilla canonical opensuse CWE-119
7.5
2015-08-16 CVE-2015-4488 Use-after-free vulnerability in the StyleAnimationValue class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 allows remote attackers to have an unspecified impact by leveraging a StyleAnimationValue::operator self assignment.
network
low complexity
oracle canonical opensuse mozilla
7.5
2015-08-16 CVE-2015-4487 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
network
low complexity
mozilla canonical opensuse oracle CWE-119
7.5
2015-08-16 CVE-2015-4475 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.
network
low complexity
mozilla canonical opensuse CWE-119
7.5
2015-07-14 CVE-2015-5143 Resource Management Errors vulnerability in multiple products
The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.
network
low complexity
djangoproject debian oracle canonical CWE-399
7.8
2015-07-14 CVE-2015-3279 Numeric Errors vulnerability in multiple products
Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, which triggers a heap-based buffer overflow.
network
low complexity
linuxfoundation canonical debian CWE-189
7.5