CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2015-6409

    Last Modified: 12 Apr 2025

    Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419.

    Published: 26 Dec 2015
    5.3
    Medium

    CVE-2015-8669

    Last Modified: 12 Apr 2025

    libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.

    Published: 26 Dec 2015
    9.8
    Critical

    CVE-2015-7554

    Last Modified: 12 Apr 2025

    The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image.

    Published: 26 Dec 2015
    6.5
    Medium

    CVE-2015-8750

    Last Modified: 20 Apr 2025

    libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked NOBITS in an ELF file.

    Published: 25 Dec 2015
    5.5
    Medium

    CVE-2015-8683

    Last Modified: 12 Apr 2025

    The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a packed TIFF image.

    Published: 25 Dec 2015
    8.3
    High

    CVE-2015-8661

    Last Modified: 12 Apr 2025

    The h264_slice_header_init function in libavcodec/h264_slice.c in FFmpeg before 2.8.3 does not validate the relationship between the number of threads and the number of slices, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted H.264 data.

    Published: 24 Dec 2015
    10
    Critical

    CVE-2015-7930

    Last Modified: 12 Apr 2025

    Adcon Telemetry A840 Telemetry Gateway Base Station has hardcoded credentials, which allows remote attackers to obtain administrative access via unspecified vectors.

    Published: 24 Dec 2015
    8.7
    High

    CVE-2015-7931

    Last Modified: 12 Apr 2025

    The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information by reading cleartext packet data, related to the lack of SSL support.

    Published: 24 Dec 2015
    7.3
    High

    CVE-2015-8662

    Last Modified: 12 Apr 2025

    The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg before 2.8.4 does not validate the number of decomposition levels before proceeding with Discrete Wavelet Transform decoding, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data.

    Published: 24 Dec 2015
    8.6
    High

    CVE-2015-7932

    Last Modified: 12 Apr 2025

    Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 24 Dec 2015
    8.6
    High

    CVE-2015-7934

    Last Modified: 12 Apr 2025

    The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to discover log-file pathnames via unspecified vectors.

    Published: 24 Dec 2015
    8.3
    High

    CVE-2015-8663

    Last Modified: 12 Apr 2025

    The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .mov file.

    Published: 24 Dec 2015
    10
    Critical

    CVE-2015-8267

    Last Modified: 12 Apr 2025

    The PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll in Dovestones AD Self Password Reset before 3.0.4.0 allows remote attackers to reset arbitrary passwords via a crafted request with a valid username.

    Published: 24 Dec 2015
    5.5
    Medium

    CVE-2015-8665

    Last Modified: 12 Apr 2025

    tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via the SamplesPerPixel tag in a TIFF image.

    Published: 24 Dec 2015
    7.9
    High

    CVE-2015-8666

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.

    Published: 24 Dec 2015
    8.8
    High

    CVE-2015-8751

    Last Modified: 21 Nov 2024

    Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.

    Published: 24 Dec 2015
    8.5
    High

    CVE-2015-7928

    Last Modified: 4 Nov 2025

    eWON devices with firmware before 10.1s0 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

    Published: 23 Dec 2015
    4.3
    Medium

    CVE-2015-7929

    Last Modified: 12 Apr 2025

    eWON devices with firmware through 10.1s0 support unspecified GET requests, which might allow remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

    Published: 23 Dec 2015
    8.8
    High

    CVE-2015-7924

    Last Modified: 12 Apr 2025

    eWON devices with firmware before 10.1s0 do not trigger the discarding of browser session data in response to a log-off action, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

    Published: 23 Dec 2015
    8
    High

    CVE-2015-7925

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to hijack the authentication of administrators for requests that trigger firmware upload, removal of configuration data, or a reboot.

    Published: 23 Dec 2015
    9.9
    Critical

    CVE-2015-7926

    Last Modified: 12 Apr 2025

    eWON devices with firmware before 10.1s0 omit RBAC for I/O server information and status requests, which allows remote attackers to obtain sensitive information via an unspecified URL.

    Published: 23 Dec 2015
    6.1
    Medium

    CVE-2015-7927

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability on eWON devices with firmware through 10.1s0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 Dec 2015
    5.3
    Medium

    CVE-2015-6471

    Last Modified: 12 Apr 2025

    Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields in Ethernet packets, which allows remote attackers to obtain sensitive information by reading packet data.

    Published: 23 Dec 2015
    9.1
    Critical

    CVE-2015-7911

    Last Modified: 12 Apr 2025

    Saia Burgess PCD1.M0xx0, PCD1.M2xx0, PCD2.M5xx0, PCD3.Mxx60, PCD3.Mxxx0, PCD7.D4xxD, PCD7.D4xxV, PCD7.D4xxWTPF, and PCD7.D4xxxT5F devices before 1.24.50 and PCD3.T665 and PCD3.T666 devices before 1.24.41 have hardcoded credentials, which allows remote attackers to obtain administrative access via an FTP session.

    Published: 23 Dec 2015
    7.5
    High

    CVE-2015-7936

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of administrators for requests that modify a password.

    Published: 23 Dec 2015
    6.7
    Medium

    CVE-2015-6851

    Last Modified: 12 Apr 2025

    EMC RSA SecurID Web Agent before 8.0 allows physically proximate attackers to bypass the privacy-screen protection mechanism by leveraging an unattended workstation and running DOM Inspector.

    Published: 23 Dec 2015
    6.5
    Medium

    CVE-2015-6431

    Last Modified: 12 Apr 2025

    Cisco IOS XE 16.1.1 allows remote attackers to cause a denial of service (device reload) via a packet with the 00-00-00-00-00-00 source MAC address, aka Bug ID CSCux48405.

    Published: 23 Dec 2015
    7.2
    High

    CVE-2015-7917

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Open Automation OPC Systems.NET 8.00.0023 and earlier allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 23 Dec 2015
    7.5
    High

    CVE-2015-7935

    Last Modified: 12 Apr 2025

    Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 23 Dec 2015
    8.8
    High

    CVE-2015-8664

    Last Modified: 12 Apr 2025

    Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106 allows remote attackers to cause a denial of service or possibly have unspecified other impact via an RGBA pixel array with crafted dimensions, a different vulnerability than CVE-2015-6792.

    Published: 23 Dec 2015
    6.5
    Medium

    CVE-2015-8701

    Last Modified: 12 Apr 2025

    QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error. It happens while processing transmit (tx) descriptors in 'tx_consume' routine, if a descriptor was to have more than allowed (ROCKER_TX_FRAGS_MAX=16) fragments. A privileged user inside guest could use this flaw to cause memory leakage on the host or crash the QEMU process instance resulting in DoS issue.

    Published: 23 Dec 2015
    7.5
    High

    CVE-2017-16023

    Last Modified: 21 Nov 2024

    Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 uses regular expressions to evaluate a string and takes unescaped separator values, which can be used to create a denial of service attack.

    Published: 23 Dec 2015
    6.8
    Medium

    CVE-2015-8373

    Last Modified: 12 Apr 2025

    The kea-dhcp4 and kea-dhcp6 servers 0.9.2 and 1.0.0-beta in ISC Kea, when certain debugging settings are used, allow remote attackers to cause a denial of service (daemon crash) via a malformed packet.

    Published: 22 Dec 2015
    6.1
    Medium

    CVE-2017-0364

    Last Modified: 21 Nov 2024

    Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.

    Published: 22 Dec 2015
    8
    High

    CVE-2015-4545

    Last Modified: 12 Apr 2025

    EMC Isilon OneFS 7.1 before 7.1.1.8, 7.2.0 before 7.2.0.4, and 7.2.1 before 7.2.1.1 allows remote authenticated administrators to bypass a SmartLock root-login restriction by creating a root account and establishing a login session.

    Published: 21 Dec 2015
    8.6
    High

    CVE-2015-7907

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.

    Published: 21 Dec 2015
    10
    Critical

    CVE-2015-7937

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to execute arbitrary code via a long password in HTTP Basic Authentication data.

    Published: 21 Dec 2015
    6.8
    Medium

    CVE-2015-8458

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in AGM.dll in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via a multiple-layer PDF document, a different vulnerability than CVE-2015-6696 and CVE-2015-6698.

    Published: 21 Dec 2015
    6.1
    Medium

    CVE-2015-4993

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4998.

    Published: 21 Dec 2015
    6.1
    Medium

    CVE-2015-4998

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-4993.

    Published: 21 Dec 2015
    4.3
    Medium

    CVE-2015-5001

    Last Modified: 12 Apr 2025

    IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 allows remote authenticated users to cause a denial of service (memory consumption) via a crafted document.

    Published: 21 Dec 2015
    8.3
    High

    CVE-2015-6480

    Last Modified: 12 Apr 2025

    The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.

    Published: 21 Dec 2015
    4.3
    Medium

    CVE-2015-7413

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF19 and 8.5.0 through CF08 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 21 Dec 2015
    8.3
    High

    CVE-2015-6481

    Last Modified: 12 Apr 2025

    The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root password, which allows remote attackers to obtain administrative access via a login session.

    Published: 21 Dec 2015
    10
    Critical

    CVE-2015-7906

    Last Modified: 12 Apr 2025

    LOYTEC LIP-3ECTB 6.0.1, LINX-100, LVIS-3E100, and LIP-ME201 devices allow remote attackers to read a password-hash backup file via unspecified vectors.

    Published: 21 Dec 2015
    9.3
    Critical

    CVE-2015-7908

    Last Modified: 12 Apr 2025

    Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allow remote attackers to discover cleartext passwords by sniffing the network.

    Published: 21 Dec 2015
    10
    Critical

    CVE-2015-7919

    Last Modified: 12 Apr 2025

    SearchBlox 8.3 before 8.3.1 allows remote attackers to write to the config file, and consequently cause a denial of service (application crash), via unspecified vectors.

    Published: 21 Dec 2015
    7.3
    High

    CVE-2015-6934

    Last Modified: 12 Apr 2025

    Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCenter Application Discovery Manager (vADM) 7.x allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

    Published: 21 Dec 2015
    7.5
    High

    CVE-2016-2070

    Last Modified: 12 Apr 2025

    The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel before 4.3.5 allows remote attackers to cause a denial of service (divide-by-zero error and system crash) via crafted TCP traffic.

    Published: 21 Dec 2015
    7.5
    High

    CVE-2015-7558

    Last Modified: 12 Apr 2025

    librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document.

    Published: 21 Dec 2015