Vulnerabilities > Code

DATE CVE VULNERABILITY TITLE RISK
2015-02-24 CVE-2013-7423 Code vulnerability in multiple products
The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.
network
low complexity
redhat opensuse canonical gnu CWE-17
5.0
2015-02-03 CVE-2015-1463 Code vulnerability in multiple products
ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization."
network
low complexity
clamav fedoraproject CWE-17
5.0
2015-02-02 CVE-2015-1452 Code vulnerability in Fortinet Fortios 5.0.7
The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWAP Access Controller) via a large number of ClientHello DTLS messages.
network
low complexity
fortinet CWE-17
7.8
2015-01-30 CVE-2014-4498 Code vulnerability in Apple mac OS X
The CPU Software in Apple OS X before 10.10.2 allows physically proximate attackers to modify firmware during the EFI update process by inserting a Thunderbolt device with crafted code in an Option ROM, aka the "Thunderstrike" issue.
local
apple CWE-17
4.7
2015-01-30 CVE-2014-4467 Code vulnerability in Apple Iphone OS
WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAME elements, which allows remote attackers to spoof the UI via a crafted web site.
network
apple CWE-17
4.3
2015-01-27 CVE-2015-1361 Code vulnerability in Google Chrome
platform/image-decoders/ImageFrame.h in Blink, as used in Google Chrome before 40.0.2214.91, does not initialize a variable that is used in calls to the Skia SkBitmap::setAlphaType function, which might allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document, a different vulnerability than CVE-2015-1205.
network
google CWE-17
6.8
2015-01-16 CVE-2015-0222 Code vulnerability in multiple products
ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.
network
low complexity
canonical djangoproject CWE-17
5.0
2015-01-16 CVE-2015-0219 Code vulnerability in Djangoproject Django
Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header.
network
low complexity
djangoproject CWE-17
5.0
2015-01-16 CVE-2014-6386 Code vulnerability in Juniper Junos
Juniper Junos 11.4 before 11.4R8, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R9, 12.3R2 before 12.3R2-S3, 12.3 before 12.3R3, 13.1 before 13.1R4, and 13.2 before 13.2R1 allows remote attackers to cause a denial of service (assertion failure and rpd restart) via a crafted BGP FlowSpec prefix.
network
low complexity
juniper CWE-17
7.8
2015-01-16 CVE-2014-6383 Code vulnerability in Juniper Junos 13.3/14.1/14.2
The stateless firewall in Juniper Junos 13.3R3, 14.1R1, and 14.1R2, when using Trio-based PFE modules, does not properly match ports, which might allow remote attackers to bypass firewall rule.
network
low complexity
juniper CWE-17
5.0