Advisories
Project ZeroExploitedCISA KEV listed2015-08-07
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
CVEs:CVE-2015-4495
GoogleExploitedCISA KEV listedHIGH2015-08-07
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript c...
CVEs:CVE-2015-4495
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| enterprise_linux_desktop |
affected |
redhat |
— |
— |
| enterprise_linux_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_tus |
affected |
redhat |
— |
— |
| enterprise_linux_workstation |
affected |
redhat |
— |
— |
| firefox |
affected |
mozilla |
— |
— |
| firefox_os |
affected |
mozilla |
— |
— |
| linux_enterprise_debuginfo |
affected |
suse |
— |
— |
| linux_enterprise_desktop |
affected |
suse |
— |
— |
| linux_enterprise_server |
affected |
suse |
— |
— |
| linux_enterprise_software_development_kit |
affected |
suse |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| solaris |
affected |
oracle |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GoogleExploitedCISA KEV listedHIGH2015-08-12
Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
CVEs:CVE-2015-1642
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| office |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2015-08-12
Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
CVEs:CVE-2015-1642
GoogleExploitedCISA KEV listedHIGH2015-08-19
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.
CVEs:CVE-2015-2502
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| internet_explorer |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2015-08-19
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.
CVEs:CVE-2015-2502
Project ZeroExploitedCISA KEV listed2015-08-12
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Mount Manager Elevation of Privilege Vulnerability."
CVEs:CVE-2015-1769
GoogleExploitedCISA KEV listedCRITICAL2015-08-12
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate att...
CVEs:CVE-2015-1769
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10 |
affected |
microsoft |
— |
— |
| windows_7 |
affected |
microsoft |
— |
— |
| windows_8 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_rt |
affected |
microsoft |
— |
— |
| windows_rt_8.1 |
affected |
microsoft |
— |
— |
| windows_server_2008 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_vista |
affected |
microsoft |
— |
— |
GooglePoC exploitCRITICAL2015-08-24
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as demonstrated by "Content Length" in...
CVEs:CVE-2015-5739
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server_tus |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
GooglePoC exploitCRITICAL2015-08-24
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers.
CVEs:CVE-2015-5740
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| enterprise_linux_server |
affected |
redhat |
— |
— |
| enterprise_linux_server_aus |
affected |
redhat |
— |
— |
| enterprise_linux_server_eus |
affected |
redhat |
— |
— |
| enterprise_linux_server_tus |
affected |
redhat |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| go |
affected |
golang |
— |
— |
Open SourcePoC exploitNONE2015-08-26
DEBIAN-CVE-2015-3239
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android-platform-external-libunwind |
affected |
Debian:12 |
android-platform-external-libunwind |
— |
| android-platform-external-libunwind |
affected |
Debian:13 |
android-platform-external-libunwind |
— |
| android-platform-external-libunwind |
affected |
Debian:11 |
android-platform-external-libunwind |
— |
| libunwind |
affected |
Debian:11 |
libunwind |
— |
| libunwind |
affected |
Debian:12 |
libunwind |
— |
| libunwind |
affected |
Debian:13 |
libunwind |
— |
| libunwind |
affected |
Debian:14 |
libunwind |
— |
GoogleEPSS <= 49%CRITICAL2015-08-24
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields.
CVEs:CVE-2015-5741
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| enterprise_linux |
affected |
redhat |
— |
— |
| go |
affected |
golang |
— |
— |
| openstack |
affected |
redhat |
— |
— |