CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2015-6378

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv05943.

    Published: 14 Dec 2015
    4
    Medium

    CVE-2015-6410

    Last Modified: 12 Apr 2025

    The Mobile and Remote Access (MRA) services implementation in Cisco Unified Communications Manager mishandles edge-device identity validation, which allows remote attackers to bypass intended call-reception and call-setup restrictions by spoofing a user, aka Bug ID CSCuu97283.

    Published: 14 Dec 2015
    7.5
    High

    CVE-2015-6401

    Last Modified: 12 Apr 2025

    Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspecified administrative functions via a crafted HTTP request, aka Bug ID CSCux24941.

    Published: 14 Dec 2015
    4.3
    Medium

    CVE-2015-6402

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCux24935.

    Published: 14 Dec 2015
    4.3
    Medium

    CVE-2015-6416

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Unified Email Interaction Manager and Unified Web Interaction Manager 11.0(1) allows remote attackers to inject arbitrary web script or HTML a crafted URL, aka Bug ID CSCuw24479.

    Published: 14 Dec 2015
    4
    Medium

    CVE-2015-6422

    Last Modified: 12 Apr 2025

    The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10.6(1) allows remote authenticated users to cause a denial of service (subapplication outage) via malformed requests, aka Bug ID CSCuu10981.

    Published: 14 Dec 2015
    2.3
    Low

    CVE-2015-8569

    Last Modified: 12 Apr 2025

    The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel through 4.3.3 do not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism via a crafted application.

    Published: 14 Dec 2015
    10
    Critical

    CVE-2015-8548

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.80, allow attackers to cause a denial of service or possibly have other impact via unknown vectors, a different issue than CVE-2015-8478.

    Published: 14 Dec 2015
    10
    Critical

    CVE-2015-8556

    Last Modified: 20 Apr 2025

    Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.

    Published: 14 Dec 2015
    7.8
    High

    CVE-2017-0750

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Upstream Linux file system. Product: Android. Versions: Android kernel. Android ID: A-36817013.

    Published: 14 Dec 2015
    9
    Critical

    CVE-2015-6389

    Last Modified: 12 Apr 2025

    Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH session and leveraging knowledge of this account's password, aka Bug ID CSCus62707.

    Published: 13 Dec 2015
    6.5
    Medium

    CVE-2015-6361

    Last Modified: 12 Apr 2025

    The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary commands via unspecified fields, aka Bug ID CSCuw86170.

    Published: 13 Dec 2015
    4.3
    Medium

    CVE-2015-6400

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547.

    Published: 13 Dec 2015
    4.3
    Medium

    CVE-2015-6418

    Last Modified: 12 Apr 2025

    The random-number generator on Cisco Small Business RV routers 4.x and SA500 security appliances 2.2.07 does not have sufficient entropy, which makes it easier for remote attackers to determine a TLS key pair via unspecified computations upon handshake key-exchange data, aka Bug ID CSCus15224.

    Published: 13 Dec 2015
    4
    Medium

    CVE-2015-6407

    Last Modified: 12 Apr 2025

    Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501.

    Published: 13 Dec 2015
    6.8
    Medium

    CVE-2015-6405

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cisco Emergency Responder 10.5(1) and 10.5(1a) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv26501.

    Published: 13 Dec 2015
    4
    Medium

    CVE-2015-6406

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files via a crafted filename, aka Bug ID CSCuv21781.

    Published: 13 Dec 2015
    4
    Medium

    CVE-2015-6413

    Last Modified: 12 Apr 2025

    Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended read-only restrictions and upload Tandberg Linux Package (TLP) files by visiting an administrative page, aka Bug ID CSCuw55651.

    Published: 13 Dec 2015
    2.1
    Low

    CVE-2015-6414

    Last Modified: 12 Apr 2025

    Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for local users to defeat cryptographic protection mechanisms by leveraging knowledge of a key from another installation, aka Bug ID CSCuw64516.

    Published: 13 Dec 2015
    7.8
    High

    CVE-2015-1336

    Last Modified: 20 Apr 2025

    The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.

    Published: 13 Dec 2015
    6.8
    Medium

    CVE-2015-6408

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cisco Unity Connection 11.5(0.98) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCux24578.

    Published: 12 Dec 2015
    6.8
    Medium

    CVE-2015-6419

    Last Modified: 12 Apr 2025

    Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via a crafted GET request, aka Bug ID CSCur25410.

    Published: 12 Dec 2015
    7.1
    High

    CVE-2015-6415

    Last Modified: 12 Apr 2025

    Cisco Unified Computing System (UCS) 2.2(3f)A on Fabric Interconnect 6200 devices allows remote attackers to cause a denial of service (CPU consumption or device outage) via a SYN flood on the SSH port during the booting process, aka Bug ID CSCuu81757.

    Published: 12 Dec 2015
    6.5
    Medium

    CVE-2015-6417

    Last Modified: 12 Apr 2025

    Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend database access, which allows remote authenticated users to read or write to database entries via (1) the GUI or (2) a crafted HTTP request, aka Bug ID CSCuv87025.

    Published: 12 Dec 2015
    6.5
    Medium

    CVE-2015-6395

    Last Modified: 12 Apr 2025

    Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the configuration via a direct request, aka Bug ID CSCuw48188.

    Published: 12 Dec 2015
    7.3
    High

    CVE-2015-8560

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.

    Published: 12 Dec 2015
    9.8
    Critical

    CVE-2015-8617

    Last Modified: 12 Apr 2025

    Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a string that is misused as a class name, leading to incorrect error handling.

    Published: 12 Dec 2015
    7
    High

    CVE-2015-8709

    Last Modified: 12 Apr 2025

    kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then using the ptrace system call. NOTE: the vendor states "there is no kernel bug here.

    Published: 12 Dec 2015
    4.3
    Medium

    CVE-2015-7040

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7041, CVE-2015-7042, and CVE-2015-7043.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7048

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.

    Published: 11 Dec 2015
    5
    Medium

    CVE-2015-7056

    Last Modified: 12 Apr 2025

    IDE SCM in Apple Xcode before 7.2 does not recognize .gitignore files, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging the presence of a file matching an ignore pattern.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7064

    Last Modified: 12 Apr 2025

    OpenGL in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-7066.

    Published: 11 Dec 2015
    2.1
    Low

    CVE-2015-7067

    Last Modified: 12 Apr 2025

    IOThunderboltFamily in Apple OS X before 10.11.2 allows local users to cause a denial of service (NULL pointer dereference) via an unspecified userclient type.

    Published: 11 Dec 2015
    9.3
    Critical

    CVE-2015-7069

    Last Modified: 12 Apr 2025

    Mobile Replayer in GPUTools Framework in Apple iOS before 9.2 allows attackers to execute arbitrary code in a privileged context via an app that provides a crafted pathname, a different vulnerability than CVE-2015-7070.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7073

    Last Modified: 12 Apr 2025

    Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted SSL handshake.

    Published: 11 Dec 2015
    7.2
    High

    CVE-2015-7076

    Last Modified: 12 Apr 2025

    The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.

    Published: 11 Dec 2015
    7.2
    High

    CVE-2015-7077

    Last Modified: 12 Apr 2025

    The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (out-of-bounds memory access) via unspecified vectors.

    Published: 11 Dec 2015
    7.2
    High

    CVE-2015-7078

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Hypervisor in Apple OS X before 10.11.2 allows local users to gain privileges via vectors involving VM objects.

    Published: 11 Dec 2015
    9.3
    Critical

    CVE-2015-7079

    Last Modified: 12 Apr 2025

    dyld in Apple iOS before 9.2 and tvOS before 9.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 11 Dec 2015
    5
    Medium

    CVE-2015-7081

    Last Modified: 12 Apr 2025

    iBooks in Apple iOS before 9.2 and OS X before 10.11.2 allows remote attackers to read arbitrary files via an iBooks file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7095

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, CVE-2015-7102, and CVE-2015-7103.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7102

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, and CVE-2015-7103.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7105

    Last Modified: 12 Apr 2025

    CoreGraphics in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file.

    Published: 11 Dec 2015
    9.3
    Critical

    CVE-2015-7111

    Last Modified: 12 Apr 2025

    The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-7112.

    Published: 11 Dec 2015
    7.2
    High

    CVE-2015-7063

    Last Modified: 12 Apr 2025

    The kernel loader in EFI in Apple OS X before 10.11.2 allows local users to gain privileges via a crafted pathname.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7001

    Last Modified: 12 Apr 2025

    AppSandbox in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 mishandles hard links, which allows attackers to bypass Contacts access revocation via a crafted app.

    Published: 11 Dec 2015
    6.8
    Medium

    CVE-2015-7038

    Last Modified: 12 Apr 2025

    Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vulnerability than CVE-2015-7039.

    Published: 11 Dec 2015
    4.3
    Medium

    CVE-2015-7041

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-2015-7040, CVE-2015-7042, and CVE-2015-7043.

    Published: 11 Dec 2015
    4.6
    Medium

    CVE-2015-7049

    Last Modified: 12 Apr 2025

    otools in Apple Xcode before 7.2 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted mach-o file, a different vulnerability than CVE-2015-7057.

    Published: 11 Dec 2015
    4.6
    Medium

    CVE-2015-7057

    Last Modified: 12 Apr 2025

    otools in Apple Xcode before 7.2 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted mach-o file, a different vulnerability than CVE-2015-7049.

    Published: 11 Dec 2015