CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2015-7222

    Last Modified: 12 Apr 2025

    Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect memory allocation and application crash) via an MP4 video file with crafted covr metadata that triggers a buffer overflow.

    Published: 16 Dec 2015
    5.3
    Medium

    CVE-2015-3223

    Last Modified: 12 Apr 2025

    The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles certain zero values, which allows remote attackers to cause a denial of service (infinite loop) via crafted packets.

    Published: 16 Dec 2015
    7.2
    High

    CVE-2015-5252

    Last Modified: 12 Apr 2025

    vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.

    Published: 16 Dec 2015
    5.4
    Medium

    CVE-2015-5296

    Last Modified: 12 Apr 2025

    Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-server data stream, related to clidfs.c, libsmb_server.c, and smbXcli_base.c.

    Published: 16 Dec 2015
    5.3
    Medium

    CVE-2015-5299

    Last Modified: 12 Apr 2025

    The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote attackers to access snapshots by visiting a shadow copy directory.

    Published: 16 Dec 2015
    10
    Critical

    CVE-2015-7202

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 16 Dec 2015
    5
    Medium

    CVE-2015-7207

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.

    Published: 16 Dec 2015
    7.5
    High

    CVE-2015-7210

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering attempted use of a data channel that has been closed by a WebRTC function.

    Published: 16 Dec 2015
    7.5
    High

    CVE-2015-7212

    Last Modified: 12 Apr 2025

    Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering a graphics operation that requires a large texture allocation.

    Published: 16 Dec 2015
    4.3
    Medium

    CVE-2015-7217

    Last Modified: 12 Apr 2025

    The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted Truevision TGA image.

    Published: 16 Dec 2015
    4
    Medium

    CVE-2015-7223

    Last Modified: 12 Apr 2025

    The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site.

    Published: 16 Dec 2015
    7.5
    High

    CVE-2015-7540

    Last Modified: 12 Apr 2025

    The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via crafted packets.

    Published: 16 Dec 2015
    10
    Critical

    CVE-2015-7203

    Last Modified: 12 Apr 2025

    Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontList.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font-family name.

    Published: 16 Dec 2015
    6.8
    Medium

    CVE-2015-7204

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 43.0 does not properly store the properties of unboxed objects, which allows remote attackers to execute arbitrary code via crafted JavaScript variable assignments.

    Published: 16 Dec 2015
    10
    Critical

    CVE-2015-7205

    Last Modified: 12 Apr 2025

    Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 might allow remote attackers to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a crafted WebRTC RTP packet.

    Published: 16 Dec 2015
    5
    Medium

    CVE-2015-7211

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified vectors.

    Published: 16 Dec 2015
    5
    Medium

    CVE-2015-7214

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.

    Published: 16 Dec 2015
    5
    Medium

    CVE-2015-7215

    Last Modified: 12 Apr 2025

    The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to information disclosure after a rethrow.

    Published: 16 Dec 2015
    5
    Medium

    CVE-2015-7218

    Last Modified: 12 Apr 2025

    The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a single-byte header frame that triggers incorrect memory allocation.

    Published: 16 Dec 2015
    5
    Medium

    CVE-2015-7219

    Last Modified: 12 Apr 2025

    The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a malformed PushPromise frame that triggers decompressed-buffer length miscalculation and incorrect memory allocation.

    Published: 16 Dec 2015
    10
    Critical

    CVE-2015-7220

    Last Modified: 12 Apr 2025

    Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.

    Published: 16 Dec 2015
    10
    Critical

    CVE-2015-7221

    Last Modified: 12 Apr 2025

    Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a deque size change.

    Published: 16 Dec 2015
    7.5
    High

    CVE-2015-8467

    Last Modified: 12 Apr 2025

    The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.

    Published: 16 Dec 2015
    4
    Medium

    CVE-2015-8575

    Last Modified: 12 Apr 2025

    The sco_sock_bind function in net/bluetooth/sco.c in the Linux kernel before 4.3.4 does not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application.

    Published: 16 Dec 2015
    6.5
    Medium

    CVE-2015-8377

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serialized data in the selected_graphs_array parameter in a save action.

    Published: 15 Dec 2015
    7.4
    High

    CVE-2015-8570

    Last Modified: 12 Apr 2025

    The password reset functionality in Lepide Active Directory Self Service allows remote authenticated users to change arbitrary domain user passwords via a crafted request.

    Published: 15 Dec 2015
    6.8
    Medium

    CVE-2015-8572

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lines in a PCX file, or (4) DataSubBlock or (5) GlobalColorTable in a GIF file.

    Published: 15 Dec 2015
    4.3
    Medium

    CVE-2015-8247

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in synnefoclient in Synnefo Internet Management Software (IMS) 2015 allows remote attackers to inject arbitrary web script or HTML via the plan_name parameter to packagehistory/listusagesdata.

    Published: 15 Dec 2015
    6.8
    Medium

    CVE-2015-8571

    Last Modified: 12 Apr 2025

    Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code via a crafted biClrUsed value in a BMP file, which triggers a buffer overflow.

    Published: 15 Dec 2015
    Unknown

    CVE-2015-5280

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 15 Dec 2015
    6.8
    Medium

    CVE-2015-7918

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in the F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allow remote attackers to execute arbitrary code via the (1) Attach, (2) DefinedName, (3) DefinedNameLocal, (4) ODBCPrepareEx, (5) ObjCreatePolygon, (6) SetTabbedTextEx, or (7) SetValidationRule method, a different vulnerability than CVE-2015-8561.

    Published: 15 Dec 2015
    6.1
    Medium

    CVE-2015-6359

    Last Modified: 12 Apr 2025

    The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles internal tables, which allows remote attackers to cause a denial of service (memory consumption or device crash) via a flood of crafted ND messages, aka Bug ID CSCup28217.

    Published: 15 Dec 2015
    6.8
    Medium

    CVE-2015-6399

    Last Modified: 12 Apr 2025

    The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial of service (IP interface outage) via crafted parameters in an HTTP request, aka Bug ID CSCuv38286.

    Published: 15 Dec 2015
    9.8
    Critical

    CVE-2015-6420

    Last Modified: 24 Feb 2026

    Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

    Published: 15 Dec 2015
    4
    Medium

    CVE-2015-5004

    Last Modified: 12 Apr 2025

    The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 does not properly encrypt data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 15 Dec 2015
    7.2
    High

    CVE-2015-6403

    Last Modified: 12 Apr 2025

    The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows local users to load a Trojan horse image by leveraging shell access, aka Bug ID CSCut67400.

    Published: 15 Dec 2015
    6.8
    Medium

    CVE-2015-8561

    Last Modified: 12 Apr 2025

    The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted integer value to the (1) AttachToSS, (2) CopyAll, (3) CopyRange, (4) CopyRangeEx, or (5) SwapTable method, a different vulnerability than CVE-2015-7918.

    Published: 15 Dec 2015
    4.3
    Medium

    CVE-2015-4206

    Last Modified: 12 Apr 2025

    Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS protection mechanism via a crafted parameter, aka Bug ID CSCuu15266.

    Published: 15 Dec 2015
    4
    Medium

    CVE-2015-6404

    Last Modified: 12 Apr 2025

    Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information by leveraging admin access and making SOAP API requests, aka Bug ID CSCuw84374.

    Published: 15 Dec 2015
    5
    Medium

    CVE-2015-6411

    Last Modified: 12 Apr 2025

    Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to obtain potentially sensitive version information by reading an unspecified field, aka Bug ID CSCux37061.

    Published: 15 Dec 2015
    9.1
    Critical

    CVE-2015-8914

    Last Modified: 12 Apr 2025

    The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a link-local source address.

    Published: 15 Dec 2015
    9.8
    Critical

    CVE-2013-7459

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

    Published: 15 Dec 2015
    8.6
    High

    CVE-2015-5259

    Last Modified: 12 Apr 2025

    Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-bounds read.

    Published: 15 Dec 2015
    7.6
    High

    CVE-2015-5343

    Last Modified: 12 Apr 2025

    Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.

    Published: 15 Dec 2015
    7.5
    High

    CVE-2015-7546

    Last Modified: 12 Apr 2025

    The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.

    Published: 15 Dec 2015
    9.8
    Critical

    CVE-2015-6792

    Last Modified: 12 Apr 2025

    The MIDI subsystem in Google Chrome before 47.0.2526.106 does not properly handle the sending of data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to midi_manager.cc, midi_manager_alsa.cc, and midi_manager_mac.cc, a different vulnerability than CVE-2015-8664.

    Published: 15 Dec 2015
    4.7
    Medium

    CVE-2015-7553

    Last Modified: 20 Apr 2025

    Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by creating netlink sockets.

    Published: 15 Dec 2015
    3.1
    Low

    CVE-2015-7561

    Last Modified: 20 Apr 2025

    Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.

    Published: 15 Dec 2015
    5
    Medium

    CVE-2015-8000

    Last Modified: 12 Apr 2025

    db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.

    Published: 15 Dec 2015
    7.1
    High

    CVE-2015-8461

    Last Modified: 12 Apr 2025

    Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via unspecified vectors.

    Published: 15 Dec 2015