Vulnerabilities > Oracle > Solaris > High

DATE CVE VULNERABILITY TITLE RISK
2015-07-14 CVE-2015-5143 Resource Management Errors vulnerability in multiple products
The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.
network
low complexity
djangoproject debian oracle canonical CWE-399
7.8
2015-07-06 CVE-2015-2728 Multiple Security vulnerability in Mozilla Firefox/Thunderbird
The IndexedDatabaseManager class in the IndexedDB implementation in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 misinterprets an unspecified IDBDatabase field as a pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors, related to a "type confusion" issue.
network
low complexity
novell mozilla oracle
7.5
2015-04-24 CVE-2015-3145 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character.
7.5
2015-04-16 CVE-2015-2578 Remote Security vulnerability in Oracle Solaris 11.2
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows remote attackers to affect availability via vectors related to Kernel IDMap.
network
oracle
7.1
2015-04-16 CVE-2015-2577 Local Security vulnerability in Oracle Solaris 10
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Accounting commands.
local
low complexity
oracle
7.2
2015-04-16 CVE-2015-0448 Local Security vulnerability in Oracle Solaris 11.2
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via vectors related to ZFS File system.
local
low complexity
oracle
7.2
2015-03-24 CVE-2015-2155 Denial of Service vulnerability in tcpdump
The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
network
low complexity
debian fedoraproject opensuse oracle tcpdump
7.5
2015-02-08 CVE-2014-9674 Remote vulnerability in FreeType Versions Prior to 2.5.4
The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
7.5
2015-02-08 CVE-2014-9663 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely calculated, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted cmap SFNT table.
7.5
2015-02-08 CVE-2014-9660 NULL Pointer Dereference vulnerability in multiple products
The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted BDF font.
7.5