CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2015-7242

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Push-Service-Mails feature in AVM FRITZ!OS before 6.30 allows remote attackers to inject arbitrary web script or HTML via the display name in the FROM field of an SIP INVITE message.

    Published: 12 Jan 2016
    7.4
    High

    CVE-2015-8400

    Last Modified: 12 Apr 2025

    The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.

    Published: 12 Jan 2016
    6.1
    Medium

    CVE-2015-4671

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the zone_id parameter to index.php.

    Published: 12 Jan 2016
    5.3
    Medium

    CVE-2015-4703

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in mysqldump_download.php in the WordPress Rename plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the dumpfname parameter.

    Published: 12 Jan 2016
    7.8
    High

    CVE-2015-8088

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7-TL10 before MT7-TL10C00B354, MT7-TL00 before MT7-TL00C01B354, and MT7-CL00 before MT7-CL00C92B354 and P8 phones with software GRA-TL00 before GRA-TL00C01B220SP01, GRA-CL00 before GRA-CL00C92B220, GRA-CL10 before GRA-CL10C92B220, GRA-UL00 before GRA-UL00C00B220, and GRA-UL10 before GRA-UL10C00B220 allows attackers to cause a denial of service (reboot) or execute arbitrary code via a crafted application.

    Published: 12 Jan 2016
    9.8
    Critical

    CVE-2015-8098

    Last Modified: 12 Apr 2025

    F5 BIG-IP APM 11.4.1 before 11.4.1 HF9, 11.5.x before 11.5.3, and 11.6.0 before 11.6.0 HF4 allow remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors related to processing a Citrix Remote Desktop connection through a virtual server configured with a remote desktop profile, aka an "Out-of-bounds memory vulnerability."

    Published: 12 Jan 2016
    7.8
    High

    CVE-2015-8306

    Last Modified: 12 Apr 2025

    Buffer overflow in the HIFI driver in Huawei P8 phones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 allows attackers to cause a denial of service (system crash) or execute arbitrary code via an unspecified parameter.

    Published: 12 Jan 2016
    5.5
    Medium

    CVE-2015-8337

    Last Modified: 12 Apr 2025

    The HIFI driver in Huawei P8 phones with software GRA-TL00 before GRA-TL00C01B220SP01, GRA-CL00 before GRA-CL00C92B220, GRA-CL10 before GRA-CL10C92B220, GRA-UL00 before GRA-UL00C00B220, GRA-UL10 before GRA-UL10C00B220 and Mate7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7-TL10 before MT7-TL10C00B354, MT7-TL00 before MT7-TL00C01B354, and MT7-CL00 before MT7-CL00C92B354 allows remote attackers to cause a denial of service (invalid memory access and reboot) via unspecified vectors related to "input null pointer as parameter."

    Published: 12 Jan 2016
    10
    Critical

    CVE-2015-8659

    Last Modified: 12 Apr 2025

    The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.

    Published: 12 Jan 2016
    8.8
    High

    CVE-2016-4342

    Last Modified: 12 Apr 2025

    ext/phar/phar_object.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 mishandles zero-length uncompressed data, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) TAR, (2) ZIP, or (3) PHAR archive.

    Published: 12 Jan 2016
    4.6
    Medium

    CVE-2016-2782

    Last Modified: 12 Apr 2025

    The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.

    Published: 12 Jan 2016
    6.5
    Medium

    CVE-2015-8605

    Last Modified: 12 Apr 2025

    ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.

    Published: 12 Jan 2016
    6.1
    Medium

    CVE-2015-7706

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to api/v3/public/shares/downloads/, the (2) authType parameter to api/v3/auth/login, or the (3) login parameter to api/v3/auth/reset_password.

    Published: 11 Jan 2016
    7.1
    High

    CVE-2015-8333

    Last Modified: 12 Apr 2025

    The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 allows remote authenticated users to change the IP address of the media server via crafted packets.

    Published: 11 Jan 2016
    8.4
    High

    CVE-2015-6566

    Last Modified: 12 Apr 2025

    zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.

    Published: 11 Jan 2016
    7.5
    High

    CVE-2015-8230

    Last Modified: 12 Apr 2025

    Memory leak in Huawei eSpace 8950 IP phones with software before V200R003C00SPC300 allows remote attackers to cause a denial of service (memory consumption and restart) via a large number of crafted ARP packets.

    Published: 11 Jan 2016
    7.5
    High

    CVE-2015-8231

    Last Modified: 12 Apr 2025

    Huawei eSpace 7910 and 7950 IP phones with software before V200R002C00SPC800 allow remote attackers with established sessions to cause a denial of service (device restart) via unspecified packets.

    Published: 11 Jan 2016
    7.4
    High

    CVE-2015-8331

    Last Modified: 12 Apr 2025

    The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 does not properly invalidate the session ID when an "abnormal exit" occurs, which allows remote attackers to conduct replay attacks via the session ID.

    Published: 11 Jan 2016
    6.5
    Medium

    CVE-2015-8335

    Last Modified: 12 Apr 2025

    Huawei VCN500 with software before V100R002C00SPC201 logs passwords in cleartext, which allows remote authenticated users to obtain sensitive information by triggering log generation and then reading the log.

    Published: 11 Jan 2016
    6.7
    Medium

    CVE-2015-7024

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Apple OS X before 10.11.1 allows local users to bypass intended Gatekeeper restrictions and gain privileges via a Trojan horse program that is loaded from an unexpected directory by an application that has a valid Apple digital signature.

    Published: 11 Jan 2016
    7.8
    High

    CVE-2015-6980

    Last Modified: 12 Apr 2025

    Directory Utility in Apple OS X before 10.11.1 mishandles authentication for new sessions, which allows local users to gain privileges via unspecified vectors.

    Published: 11 Jan 2016
    5.3
    Medium

    CVE-2015-7399

    Last Modified: 12 Apr 2025

    IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to obtain sensitive information about the HTTP server via unspecified vectors.

    Published: 11 Jan 2016
    9.8
    Critical

    CVE-2015-8608

    Last Modified: 20 Apr 2025

    The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument.

    Published: 11 Jan 2016
    4.6
    Medium

    CVE-2015-7566

    Last Modified: 12 Apr 2025

    The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a bulk-out endpoint.

    Published: 11 Jan 2016
    7.8
    High

    CVE-2016-10729

    Last Modified: 21 Nov 2024

    An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.

    Published: 11 Jan 2016
    7.3
    High

    CVE-2015-8607

    Last Modified: 12 Apr 2025

    The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.

    Published: 11 Jan 2016
    7.7
    High

    CVE-2016-1905

    Last Modified: 12 Apr 2025

    The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.

    Published: 11 Jan 2016
    8.8
    High

    CVE-2015-7465

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 10 Jan 2016
    7.4
    High

    CVE-2015-7397

    Last Modified: 12 Apr 2025

    Multiple open redirect vulnerabilities in the Aurora starter store in IBM WebSphere Commerce 7.0 through Feature Pack 8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referrer parameter.

    Published: 10 Jan 2016
    4.3
    Medium

    CVE-2015-7115

    Last Modified: 12 Apr 2025

    libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7116.

    Published: 10 Jan 2016
    4.3
    Medium

    CVE-2015-7116

    Last Modified: 12 Apr 2025

    libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-7115.

    Published: 10 Jan 2016
    3.1
    Low

    CVE-2015-7466

    Last Modified: 12 Apr 2025

    Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended query restrictions or modify the LDAP directory, via unspecified vectors.

    Published: 10 Jan 2016
    8.8
    High

    CVE-2016-4343

    Last Modified: 12 Apr 2025

    The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which allows remote attackers to cause a denial of service (uninitialized pointer dereference) or possibly have unspecified other impact via a crafted TAR archive.

    Published: 10 Jan 2016
    7.5
    High

    CVE-2016-10712

    Last Modified: 21 Nov 2024

    In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = stream_get_meta_data(fopen($file, "r"))['uri']" call mishandles the case where $file is data:text/plain;uri=eviluri, -- in other words, metadata can be set by an attacker.

    Published: 10 Jan 2016
    6.6
    Medium

    CVE-2015-7088

    Last Modified: 12 Apr 2025

    Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.

    Published: 9 Jan 2016
    9.6
    Critical

    CVE-2015-7939

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary code via a long vlp filename.

    Published: 9 Jan 2016
    6.6
    Medium

    CVE-2015-7085

    Last Modified: 12 Apr 2025

    Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.

    Published: 9 Jan 2016
    6.6
    Medium

    CVE-2015-7089

    Last Modified: 12 Apr 2025

    Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.

    Published: 9 Jan 2016
    6.1
    Medium

    CVE-2015-8510

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescreen app in Mozilla Firefox OS before 2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted web site that is mishandled during "Add to home screen" bookmarking.

    Published: 9 Jan 2016
    6.3
    Medium

    CVE-2015-6933

    Last Modified: 12 Apr 2025

    The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 allows Windows guest OS users to gain guest OS privileges or cause a denial of service (guest OS kernel memory corruption) via unspecified vectors.

    Published: 9 Jan 2016
    6.6
    Medium

    CVE-2015-7086

    Last Modified: 12 Apr 2025

    Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.

    Published: 9 Jan 2016
    6.6
    Medium

    CVE-2015-7087

    Last Modified: 12 Apr 2025

    Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.

    Published: 9 Jan 2016
    6.6
    Medium

    CVE-2015-7090

    Last Modified: 12 Apr 2025

    Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.

    Published: 9 Jan 2016
    6.6
    Medium

    CVE-2015-7091

    Last Modified: 12 Apr 2025

    Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7092, and CVE-2015-7117.

    Published: 9 Jan 2016
    6.6
    Medium

    CVE-2015-7092

    Last Modified: 12 Apr 2025

    Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted TXXX frame within an ID3 tag in MP3 data in a movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, and CVE-2015-7117.

    Published: 9 Jan 2016
    6.6
    Medium

    CVE-2015-7117

    Last Modified: 12 Apr 2025

    Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, and CVE-2015-7092.

    Published: 9 Jan 2016
    9.8
    Critical

    CVE-2015-7938

    Last Modified: 12 Apr 2025

    Advantech EKI-132x devices with firmware before 2015-12-31 allow remote attackers to bypass authentication via unspecified vectors.

    Published: 9 Jan 2016
    6.4
    Medium

    CVE-2015-8511

    Last Modified: 12 Apr 2025

    Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.

    Published: 9 Jan 2016
    4.6
    Medium

    CVE-2015-8512

    Last Modified: 12 Apr 2025

    The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by entering many passcode guesses.

    Published: 9 Jan 2016
    6.1
    Medium

    CVE-2014-6444

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Titan Framework plugin before 1.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) t parameter to iframe-googlefont-preview.php or the (2) text parameter to iframe-font-preview.php.

    Published: 8 Jan 2016