CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2015-8376

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Navigation Group, or (3) Label parameter to blueprints/sections/edit/1.

    Published: 8 Jan 2016
    6.1
    Medium

    CVE-2016-1498

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the OCS discovery provider component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a URL.

    Published: 8 Jan 2016
    3.1
    Low

    CVE-2016-1500

    Last Modified: 12 Apr 2025

    ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share.

    Published: 8 Jan 2016
    4.3
    Medium

    CVE-2016-1501

    Last Modified: 12 Apr 2025

    ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages.

    Published: 8 Jan 2016
    6.1
    Medium

    CVE-2015-8766

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) email_sendmail[from_name], (2) email_sendmail[from_address], (3) email_smtp[from_name], (4) email_smtp[from_address], (5) email_smtp[host], (6) email_smtp[port], (7) jit_image_manipulation[trusted_external_sites], or (8) maintenance_mode[ip_whitelist] parameters to system/preferences.

    Published: 8 Jan 2016
    6.1
    Medium

    CVE-2016-1565

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Field Group module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with permission to configure field display settings to inject arbitrary web script or HTML via an element attribute.

    Published: 8 Jan 2016
    6.1
    Medium

    CVE-2014-7151

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the NEX-Forms Lite plugin 2.1.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the form_fields parameter in a (1) do_edit or (2) do_insert action to wp-admin/admin-ajax.php.

    Published: 8 Jan 2016
    10
    Critical

    CVE-2015-7541

    Last Modified: 12 Apr 2025

    The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary code via shell metacharacters in the (1) image_path, (2) colors, or (3) depth variable.

    Published: 8 Jan 2016
    8.5
    High

    CVE-2016-1499

    Last Modified: 12 Apr 2025

    ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/scan.php.

    Published: 8 Jan 2016
    8.1
    High

    CVE-2014-8886

    Last Modified: 12 Apr 2025

    AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote attackers to create symlinks or overwrite critical files, and consequently execute arbitrary code, via a crafted firmware image.

    Published: 8 Jan 2016
    8.6
    High

    CVE-2015-4694

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.

    Published: 8 Jan 2016
    8.3
    High

    CVE-2015-8765

    Last Modified: 12 Apr 2025

    Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remote attackers to execute arbitrary code via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

    Published: 8 Jan 2016
    4.7
    Medium

    CVE-2015-7328

    Last Modified: 12 Apr 2025

    Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permissions for the private key of the Certification Authority (CA) certificate during the initial installation and configuration, which might allow local users to obtain sensitive information via unspecified vectors.

    Published: 8 Jan 2016
    7.8
    High

    CVE-2015-7362

    Last Modified: 12 Apr 2025

    Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable and executable, allows local users to gain privileges via the helper/subroc setuid program.

    Published: 8 Jan 2016
    3.3
    Low

    CVE-2015-7758

    Last Modified: 12 Apr 2025

    Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .toc extension for the file name, as demonstrated by .thesis.tex.aux.

    Published: 8 Jan 2016
    8.4
    High

    CVE-2015-8612

    Last Modified: 12 Apr 2025

    The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users to gain privileges via the dhcp_handler argument.

    Published: 8 Jan 2016
    9.1
    Critical

    CVE-2015-8753

    Last Modified: 12 Apr 2025

    SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insecure signature," aka SAP Security Note 2134905.

    Published: 8 Jan 2016
    7.5
    High

    CVE-2015-8754

    Last Modified: 12 Apr 2025

    The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and modify the mollom blacklist via unspecified vectors.

    Published: 8 Jan 2016
    5.5
    Medium

    CVE-2015-8225

    Last Modified: 12 Apr 2025

    The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL00C00B220 and ALE-TL00C01B220 and GEM-703L smartphones with software before V100R001C233B111 allows remote attackers to cause a denial of service (crash) via a crafted application with the system or camera permission, a different vulnerability than CVE-2015-8226.

    Published: 8 Jan 2016
    7.5
    High

    CVE-2015-8547

    Last Modified: 12 Apr 2025

    The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query.

    Published: 8 Jan 2016
    7.4
    High

    CVE-2015-8597

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in Blue Coat ProxySG 6.5 before 6.5.8.8 and 6.6 and Advanced Secure Gateway (ASG) 6.6 might allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a base64-encoded URL in conjunction with a "clear text" one in a coaching page, as demonstrated by "http://www.%humbug-URL%.local/bluecoat-splash-API?%BASE64-URL%."

    Published: 8 Jan 2016
    5.4
    Medium

    CVE-2015-8755

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.

    Published: 8 Jan 2016
    5.4
    Medium

    CVE-2015-8756

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in TYPO3 6.2.x before 6.2.16 allows remote authenticated editors to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Jan 2016
    5.4
    Medium

    CVE-2015-8759

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated editors to inject arbitrary web script or HTML via a link field.

    Published: 8 Jan 2016
    6.1
    Medium

    CVE-2015-8760

    Last Modified: 12 Apr 2025

    The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing."

    Published: 8 Jan 2016
    7.8
    High

    CVE-2015-6856

    Last Modified: 12 Apr 2025

    Dell Pre-Boot Authentication Driver (PBADRV.sys) 1.0.1.5 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x0022201c IOCTL call.

    Published: 8 Jan 2016
    8.1
    High

    CVE-2015-7754

    Last Modified: 12 Apr 2025

    Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or execute arbitrary code via crafted SSH negotiation.

    Published: 8 Jan 2016
    5.5
    Medium

    CVE-2015-8226

    Last Modified: 12 Apr 2025

    The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL00C00B220 and ALE-TL00C01B220 and GEM-703L smartphones with software before V100R001C233B111 allows remote attackers to cause a denial of service (crash) via a crafted application with the system or camera permission, a different vulnerability than CVE-2015-8225.

    Published: 8 Jan 2016
    4
    Medium

    CVE-2015-8303

    Last Modified: 12 Apr 2025

    Huawei Document Security Management (DSM) with software before V100R002C05SPC661 does not clear the clipboard when closing a secure file, which allows local users to obtain sensitive information by pasting the contents to another file.

    Published: 8 Jan 2016
    3.1
    Low

    CVE-2015-8481

    Last Modified: 12 Apr 2025

    Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup referencing an image attachment, which might allow remote attackers to obtain sensitive information by updating a different issue that includes wiki markup for an external image reference.

    Published: 8 Jan 2016
    6.1
    Medium

    CVE-2015-8757

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to extension data during an extension installation.

    Published: 8 Jan 2016
    5.4
    Medium

    CVE-2015-8758

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in unspecified frontend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors.

    Published: 8 Jan 2016
    9
    Critical

    CVE-2015-8761

    Last Modified: 12 Apr 2025

    The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools import.

    Published: 8 Jan 2016
    6.5
    Medium

    CVE-2015-6433

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCut66767.

    Published: 8 Jan 2016
    6.1
    Medium

    CVE-2015-6434

    Last Modified: 12 Apr 2025

    Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCux64856.

    Published: 8 Jan 2016
    9.8
    Critical

    CVE-2015-8261

    Last Modified: 12 Apr 2025

    The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.

    Published: 8 Jan 2016
    8.4
    High

    CVE-2015-6862

    Last Modified: 12 Apr 2025

    HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.

    Published: 8 Jan 2016
    7.8
    High

    CVE-2016-1131

    Last Modified: 12 Apr 2025

    Buffer overflow in the CL_vsprintf function in Takumi Yamada DX Library before 3.16 allows remote attackers to execute arbitrary code via a crafted string.

    Published: 8 Jan 2016
    5.3
    Medium

    CVE-2015-8629

    Last Modified: 12 Apr 2025

    The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted string.

    Published: 8 Jan 2016
    7.5
    High

    CVE-2015-8630

    Last Modified: 12 Apr 2025

    The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by specifying KADM5_POLICY with a NULL policy name.

    Published: 8 Jan 2016
    6.5
    Medium

    CVE-2015-8631

    Last Modified: 12 Apr 2025

    Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.

    Published: 8 Jan 2016
    9.8
    Critical

    CVE-2016-0726

    Last Modified: 20 Apr 2025

    The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.

    Published: 8 Jan 2016
    8.8
    High

    CVE-2016-1568

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.

    Published: 8 Jan 2016
    5.9
    Medium

    CVE-2015-8749

    Last Modified: 12 Apr 2025

    The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.

    Published: 7 Jan 2016
    7.5
    High

    CVE-2016-7539

    Last Modified: 20 Apr 2025

    Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

    Published: 7 Jan 2016
    3.5
    Low

    CVE-2015-7548

    Last Modified: 12 Apr 2025

    OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.

    Published: 7 Jan 2016
    9.8
    Critical

    CVE-2015-6642

    Last Modified: 12 Apr 2025

    The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24157888.

    Published: 6 Jan 2016
    6.6
    Medium

    CVE-2015-6643

    Last Modified: 12 Apr 2025

    Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximate attackers to modify settings or bypass a reset protection mechanism via unspecified vectors, aka internal bug 25290269.

    Published: 6 Jan 2016
    9.8
    Critical

    CVE-2015-6636

    Last Modified: 12 Apr 2025

    mediaserver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 25070493 and 24686670.

    Published: 6 Jan 2016
    7.8
    High

    CVE-2015-6637

    Last Modified: 12 Apr 2025

    The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 25307013.

    Published: 6 Jan 2016