CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2015-3268

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to inject arbitrary web script or HTML via the description attribute of a display-entity element.

    Published: 12 Apr 2016
    6.5
    Medium

    CVE-2015-5167

    Last Modified: 12 Apr 2025

    The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API.

    Published: 12 Apr 2016
    4.3
    Medium

    CVE-2015-8021

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 11.4.0 before HF8 and 11.4.1 before HF6; BIG-IP AFM and PEM 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; and BIG-IP Edge Gateway, WebAccelerator, and WOM 11.x before 11.2.1 HF11 and 11.3.0 allows remote authenticated users to upload files via uploadImage.php.

    Published: 12 Apr 2016
    4.3
    Medium

    CVE-2015-8473

    Last Modified: 12 Apr 2025

    The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.

    Published: 12 Apr 2016
    5.3
    Medium

    CVE-2015-8346

    Last Modified: 12 Apr 2025

    app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.

    Published: 12 Apr 2016
    7.4
    High

    CVE-2015-8474

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted back_url parameter, as demonstrated by "@attacker.com," a different vulnerability than CVE-2014-1985.

    Published: 12 Apr 2016
    5.3
    Medium

    CVE-2015-8537

    Last Modified: 12 Apr 2025

    app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive information by viewing an Atom feed.

    Published: 12 Apr 2016
    8.6
    High

    CVE-2015-8702

    Last Modified: 12 Apr 2025

    The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid character in a PTR response, as demonstrated by a "\032" (whitespace) character in a hostname.

    Published: 12 Apr 2016
    9.8
    Critical

    CVE-2016-0733

    Last Modified: 12 Apr 2025

    The Admin UI in Apache Ranger before 0.5.1 does not properly handle authentication requests that lack a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid username.

    Published: 12 Apr 2016
    9.8
    Critical

    CVE-2016-2170

    Last Modified: 12 Apr 2025

    Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

    Published: 12 Apr 2016
    7.8
    High

    CVE-2016-2556

    Last Modified: 12 Apr 2025

    The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows improperly allows access to restricted functionality, which allows local users to gain privileges via unspecified vectors.

    Published: 12 Apr 2016
    8.4
    High

    CVE-2016-2558

    Last Modified: 12 Apr 2025

    The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows allows local users to obtain sensitive information, cause a denial of service (crash), or gain privileges via unspecified vectors related to an untrusted pointer, which trigger uninitialized or out-of-bounds memory access.

    Published: 12 Apr 2016
    8.4
    High

    CVE-2016-2557

    Last Modified: 12 Apr 2025

    The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows allows local users to obtain sensitive information from kernel memory, cause a denial of service (crash), or possibly gain privileges via unspecified vectors, which trigger uninitialized or out-of-bounds memory access.

    Published: 12 Apr 2016
    6.3
    Medium

    CVE-2016-2111

    Last Modified: 12 Apr 2025

    The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoint, and obtain sensitive session information, by running a crafted application and leveraging the ability to sniff network traffic, a related issue to CVE-2015-0005.

    Published: 12 Apr 2016
    5.9
    Medium

    CVE-2016-2114

    Last Modified: 12 Apr 2025

    The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB servers by modifying the client-server data stream.

    Published: 12 Apr 2016
    5.9
    Medium

    CVE-2016-2115

    Last Modified: 12 Apr 2025

    Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.

    Published: 12 Apr 2016
    7.8
    High

    CVE-2016-3991

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the loadImage function in the tiffcrop tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted TIFF image with zero tiles.

    Published: 12 Apr 2016
    5.9
    Medium

    CVE-2015-5370

    Last Modified: 12 Apr 2025

    Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (application crash or CPU consumption), or possibly execute arbitrary code on a client system via unspecified vectors.

    Published: 12 Apr 2016
    7.4
    High

    CVE-2016-2113

    Last Modified: 12 Apr 2025

    Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive information via a crafted certificate.

    Published: 12 Apr 2016
    5.9
    Medium

    CVE-2016-2110

    Last Modified: 12 Apr 2025

    The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-server data stream to remove application-layer flags or encryption settings, as demonstrated by clearing the NTLMSSP_NEGOTIATE_SEAL or NTLMSSP_NEGOTIATE_SIGN option to disrupt LDAP security.

    Published: 12 Apr 2016
    5.9
    Medium

    CVE-2016-2112

    Last Modified: 12 Apr 2025

    The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perform LDAP protocol-downgrade attacks by modifying the client-server data stream.

    Published: 12 Apr 2016
    7.5
    High

    CVE-2016-2118

    Last Modified: 12 Apr 2025

    The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka "BADLOCK."

    Published: 12 Apr 2016
    7.8
    High

    CVE-2016-3990

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the horizontalDifference8 function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted TIFF image to tiffcp.

    Published: 12 Apr 2016
    4.3
    Medium

    CVE-2015-8399

    Last Modified: 12 Apr 2025

    Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.

    Published: 11 Apr 2016
    8.8
    High

    CVE-2015-8604

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.

    Published: 11 Apr 2016
    5.3
    Medium

    CVE-2014-9759

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obtain sensitive master salt configuration information via a SOAP API request.

    Published: 11 Apr 2016
    8.8
    High

    CVE-2015-7330

    Last Modified: 12 Apr 2025

    Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet communications protocol.

    Published: 11 Apr 2016
    6.1
    Medium

    CVE-2015-8398

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.

    Published: 11 Apr 2016
    7.3
    High

    CVE-2015-8614

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion.

    Published: 11 Apr 2016
    7.3
    High

    CVE-2015-8708

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a crafted email, involving Japanese character set conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8614.

    Published: 11 Apr 2016
    6.1
    Medium

    CVE-2015-0265

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Policy Admin Tool in Apache Ranger before 0.5.0 allows remote attackers to inject arbitrary web script or HTML via the HTTP User-Agent header.

    Published: 11 Apr 2016
    7.1
    High

    CVE-2015-0266

    Last Modified: 12 Apr 2025

    The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to module URLs.

    Published: 11 Apr 2016
    8.8
    High

    CVE-2016-0735

    Last Modified: 12 Apr 2025

    Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishandling of a resource-level exclude policy.

    Published: 11 Apr 2016
    7.5
    High

    CVE-2012-6699

    Last Modified: 12 Apr 2025

    The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response.

    Published: 11 Apr 2016
    8.8
    High

    CVE-2016-1235

    Last Modified: 12 Apr 2025

    The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options.

    Published: 11 Apr 2016
    7.5
    High

    CVE-2012-6698

    Last Modified: 12 Apr 2025

    The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted response.

    Published: 11 Apr 2016
    7.5
    High

    CVE-2012-6700

    Last Modified: 12 Apr 2025

    The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response.

    Published: 11 Apr 2016
    7.5
    High

    CVE-2016-3678

    Last Modified: 12 Apr 2025

    Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 allow remote attackers to cause a denial of service (switch restart) via crafted traffic.

    Published: 11 Apr 2016
    9.8
    Critical

    CVE-2016-2385

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a denial of service (memory corruption and process crash) or possibly execute arbitrary code via a large SIP packet.

    Published: 11 Apr 2016
    8.8
    High

    CVE-2016-3659

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter.

    Published: 11 Apr 2016
    6.4
    Medium

    CVE-2016-3676

    Last Modified: 12 Apr 2025

    Huawei E3276s USB modems with software before E3276s-150TCPU-V200R002B436D09SP00C00 allow man-in-the-middle attackers to intercept, spoof, or modify network traffic via unspecified vectors related to a fake network.

    Published: 11 Apr 2016
    8.1
    High

    CVE-2016-3675

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to system databases.

    Published: 11 Apr 2016
    7.2
    High

    CVE-2016-0709

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) in a ZIP archive entry, as demonstrated by "../../webapps/x.jsp."

    Published: 11 Apr 2016
    7.5
    High

    CVE-2016-0783

    Last Modified: 12 Apr 2025

    The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user passwords by leveraging knowledge of a user name and the current system time.

    Published: 11 Apr 2016
    7.5
    High

    CVE-2016-2164

    Last Modified: 12 Apr 2025

    The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checking the specified protocol handler, which allows remote attackers to read arbitrary files by attempting to upload a file.

    Published: 11 Apr 2016
    7.5
    High

    CVE-2016-2171

    Last Modified: 12 Apr 2025

    The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.

    Published: 11 Apr 2016
    7.5
    High

    CVE-2015-8240

    Last Modified: 12 Apr 2025

    The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and BIG-IP PEM before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.0 HF6 and BIG-IP PSM before 11.4.1 HF10 does not properly handle TCP options, which allows remote attackers to cause a denial of service via unspecified vectors, related to the tm.minpathmtu database variable.

    Published: 11 Apr 2016
    8.8
    High

    CVE-2016-0710

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/.

    Published: 11 Apr 2016
    6.5
    Medium

    CVE-2016-0784

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry.

    Published: 11 Apr 2016
    6.1
    Medium

    CVE-2016-0711

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource.

    Published: 11 Apr 2016