CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2015-8484

    Last Modified: 12 Apr 2025

    Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended calendar-viewing restrictions via unspecified vectors, a different vulnerability than CVE-2015-8485, CVE-2015-8486, and CVE-2016-1152.

    Published: 17 Feb 2016
    5.4
    Medium

    CVE-2015-8485

    Last Modified: 12 Apr 2025

    Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary posting titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8486, and CVE-2016-1152.

    Published: 17 Feb 2016
    4.3
    Medium

    CVE-2015-8488

    Last Modified: 12 Apr 2025

    Cybozu Office 10.3.0 allows remote attackers to read image files via a crafted e-mail message, a different vulnerability than CVE-2015-8487.

    Published: 17 Feb 2016
    6.5
    Medium

    CVE-2015-8489

    Last Modified: 12 Apr 2025

    customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service (excessive database locking) via a crafted CSV file, a different vulnerability than CVE-2016-1153.

    Published: 17 Feb 2016
    6.5
    Medium

    CVE-2016-1153

    Last Modified: 12 Apr 2025

    customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different vulnerability than CVE-2015-8489.

    Published: 17 Feb 2016
    7.5
    High

    CVE-2016-2094

    Last Modified: 12 Apr 2025

    The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshake, aka a read-timeout vulnerability.

    Published: 17 Feb 2016
    5.5
    Medium

    CVE-2016-2142

    Last Modified: 12 Apr 2025

    Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by reading the file.

    Published: 17 Feb 2016
    8.4
    High

    CVE-2016-2857

    Last Modified: 12 Apr 2025

    The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.

    Published: 17 Feb 2016
    5.5
    Medium

    CVE-2016-2271

    Last Modified: 12 Apr 2025

    VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors related to a non-canonical RIP.

    Published: 17 Feb 2016
    6.8
    Medium

    CVE-2016-2270

    Last Modified: 12 Apr 2025

    Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.

    Published: 17 Feb 2016
    5.3
    Medium

    CVE-2016-2388

    Last Modified: 21 Apr 2026

    The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.

    Published: 16 Feb 2016
    9.8
    Critical

    CVE-2016-2386

    Last Modified: 21 Apr 2026

    SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

    Published: 16 Feb 2016
    6.1
    Medium

    CVE-2016-2387

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Java Proxy Runtime ProxyServer servlet in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) ns or (2) interface parameter to ProxyServer/register, aka SAP Security Note 2220571.

    Published: 16 Feb 2016
    7.5
    High

    CVE-2016-2389

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978.

    Published: 16 Feb 2016
    6.1
    Medium

    CVE-2015-7578

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes.

    Published: 16 Feb 2016
    6.1
    Medium

    CVE-2015-7579

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the Rails::Html::FullSanitizer class.

    Published: 16 Feb 2016
    6.1
    Medium

    CVE-2015-7580

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node.

    Published: 16 Feb 2016
    8.8
    High

    CVE-2016-0720

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.

    Published: 16 Feb 2016
    7.1
    High

    CVE-2016-3185

    Last Modified: 12 Apr 2025

    The make_http_soap_request function in ext/soap/php_http.c in PHP before 5.4.44, 5.5.x before 5.5.28, 5.6.x before 5.6.12, and 7.x before 7.0.4 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (type confusion and application crash) via crafted serialized _cookies data, related to the SoapClient::__call method in ext/soap/soap.c.

    Published: 16 Feb 2016
    8.1
    High

    CVE-2015-7547

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

    Published: 16 Feb 2016
    8.1
    High

    CVE-2016-0721

    Last Modified: 20 Apr 2025

    Session fixation vulnerability in pcsd in pcs before 0.9.157.

    Published: 16 Feb 2016
    5.9
    Medium

    CVE-2016-2390

    Last Modified: 12 Apr 2025

    The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (application crash) via a plaintext HTTP message.

    Published: 16 Feb 2016
    5
    Medium

    CVE-2016-2391

    Last Modified: 12 Apr 2025

    The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.

    Published: 16 Feb 2016
    4.3
    Medium

    CVE-2016-0231

    Last Modified: 12 Apr 2025

    IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs.

    Published: 15 Feb 2016
    4.3
    Medium

    CVE-2016-0232

    Last Modified: 12 Apr 2025

    IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading README files.

    Published: 15 Feb 2016
    5.8
    Medium

    CVE-2016-1321

    Last Modified: 12 Apr 2025

    Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to bypass a certain certificate-validation feature and obtain sensitive firmware-image and IP address data via a request to an unspecified Cisco server, aka Bug ID CSCut98082.

    Published: 15 Feb 2016
    6.5
    Medium

    CVE-2016-1330

    Last Modified: 12 Apr 2025

    Cisco IOS 15.2(4)E on Industrial Ethernet 2000 devices allows remote attackers to cause a denial of service (device reload) via crafted Cisco Discovery Protocol (CDP) packets, aka Bug ID CSCuy27746.

    Published: 15 Feb 2016
    6.1
    Medium

    CVE-2016-1331

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuy10766.

    Published: 15 Feb 2016
    4.4
    Medium

    CVE-2015-2008

    Last Modified: 12 Apr 2025

    IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.6 includes SSH private keys during backup operations, which allows remote authenticated administrators to obtain sensitive information by reading a backup archive.

    Published: 15 Feb 2016
    8.8
    High

    CVE-2015-5050

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 15 Feb 2016
    5.4
    Medium

    CVE-2015-7398

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 15 Feb 2016
    6.1
    Medium

    CVE-2015-8795

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled during the rendering of the (1) Analysis page, related to webapp/web/js/scripts/analysis.js or (2) Schema-Browser page, related to webapp/web/js/scripts/schema-browser.js.

    Published: 15 Feb 2016
    6.1
    Medium

    CVE-2015-8797

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter to a plugins/cache URI.

    Published: 15 Feb 2016
    4.9
    Medium

    CVE-2016-2314

    Last Modified: 12 Apr 2025

    GlobespanVirata ftpd 1.0, as used on Huawei SmartAX MT882 devices V200R002B022 Arg, allows remote authenticated users to cause a denial of service (device outage) by using the FTP MKD command to create a directory with a long name, and then using certain other commands.

    Published: 15 Feb 2016
    7.4
    High

    CVE-2015-4956

    Last Modified: 12 Apr 2025

    The Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to execute unspecified OS commands via unknown vectors.

    Published: 15 Feb 2016
    5.4
    Medium

    CVE-2015-4957

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 15 Feb 2016
    4
    Medium

    CVE-2015-4991

    Last Modified: 12 Apr 2025

    IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain sensitive information by reading a dump file.

    Published: 15 Feb 2016
    7.5
    High

    CVE-2015-5010

    Last Modified: 12 Apr 2025

    IBM Security Access Manager for Web 7.0 before 7.0.0 IF21, 8.0 before 8.0.1.3 IF4, and 9.0 before 9.0.0.1 IF1 does not have a lockout mechanism for invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 15 Feb 2016
    7.5
    High

    CVE-2015-5012

    Last Modified: 12 Apr 2025

    The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

    Published: 15 Feb 2016
    7.5
    High

    CVE-2015-5042

    Last Modified: 12 Apr 2025

    IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote attackers to execute arbitrary code by including a crafted Flash file.

    Published: 15 Feb 2016
    7.2
    High

    CVE-2015-7472

    Last Modified: 12 Apr 2025

    IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before CF10 allows remote attackers to conduct LDAP injection attacks, and consequently read or write to repository data, via unspecified vectors.

    Published: 15 Feb 2016
    6.1
    Medium

    CVE-2015-8531

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Web 8.0 before 8.0.1.3 IF4 and 9.0 before 9.0.0.1 IF1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 15 Feb 2016
    5.3
    Medium

    CVE-2015-2005

    Last Modified: 12 Apr 2025

    IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.

    Published: 15 Feb 2016
    3.7
    Low

    CVE-2015-7408

    Last Modified: 12 Apr 2025

    The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy authority.

    Published: 15 Feb 2016
    5.3
    Medium

    CVE-2015-7444

    Last Modified: 12 Apr 2025

    The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to obtain sensitive information via unspecified vectors.

    Published: 15 Feb 2016
    5.4
    Medium

    CVE-2015-7492

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Reference Data Management (RDM) in IBM InfoSphere Master Data Management 10.1, 11.0 before FP5, 11.3, 11.4, and 11.5 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 15 Feb 2016
    6.1
    Medium

    CVE-2015-8796

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted schema-browse URL.

    Published: 15 Feb 2016
    9.8
    Critical

    CVE-2016-2231

    Last Modified: 12 Apr 2025

    The Windows-based Host Interface Program (WHIP) service on Huawei SmartAX MT882 devices V200R002B022 Arg relies on the client to send a length field that is consistent with a buffer size, which allows remote attackers to cause a denial of service (device outage) or possibly have unspecified other impact via crafted traffic on TCP port 8701.

    Published: 15 Feb 2016
    7.8
    High

    CVE-2016-0795

    Last Modified: 12 Apr 2025

    LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.

    Published: 15 Feb 2016
    7.8
    High

    CVE-2016-0794

    Last Modified: 12 Apr 2025

    The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.

    Published: 15 Feb 2016