CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2015-1344

    Last Modified: 12 Apr 2025

    The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writing a pid to the tasks file.

    Published: 7 Dec 2015
    5
    Medium

    CVE-2015-4334

    Last Modified: 12 Apr 2025

    The default configuration of SGOS in Blue Coat ProxySG before 6.2.16.5, 6.5 before 6.5.7.1, and 6.6 before 6.6.2.1 forwards authentication challenges from upstream origin content servers (OCS) when used in an explicit proxy deployment, which makes it easier for remote attackers to obtain sensitive information via a 407 (aka Proxy Authentication Required) HTTP status code, as demonstrated when using NTLM authentication.

    Published: 7 Dec 2015
    2.1
    Low

    CVE-2015-8482

    Last Modified: 12 Apr 2025

    Blue Coat Unified Agent before 4.6.2 does not prevent modification of its configuration files when running in local enforcement mode, which allows local administrators to unblock categories or disable the agent via unspecified vectors.

    Published: 7 Dec 2015
    3.7
    Low

    CVE-2015-7519

    Last Modified: 12 Apr 2025

    agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X_User header.

    Published: 7 Dec 2015
    7
    High

    CVE-2015-7543

    Last Modified: 20 Apr 2025

    aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.

    Published: 7 Dec 2015
    9.1
    Critical

    CVE-2015-7544

    Last Modified: 20 Apr 2025

    redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.

    Published: 7 Dec 2015
    6.5
    Medium

    CVE-2015-8538

    Last Modified: 20 Apr 2025

    dwarf_leb.c in libdwarf allows attackers to cause a denial of service (SIGSEGV).

    Published: 7 Dec 2015
    6.1
    Medium

    CVE-2020-28724

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.

    Published: 6 Dec 2015
    7.5
    High

    CVE-2015-3194

    Last Modified: 12 Apr 2025

    crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter.

    Published: 6 Dec 2015
    4.3
    Medium

    CVE-2015-6387

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573.

    Published: 5 Dec 2015
    4.9
    Medium

    CVE-2015-6394

    Last Modified: 12 Apr 2025

    The kernel in Cisco NX-OS 5.2(9)N1(1) on Nexus 5000 devices allows local users to cause a denial of service (device crash) via crafted USB parameters, aka Bug ID CSCus89408.

    Published: 5 Dec 2015
    4.3
    Medium

    CVE-2015-6384

    Last Modified: 12 Apr 2025

    The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom application permissions, which allows attackers to bypass intended access restrictions via a crafted application, aka Bug ID CSCuw86442.

    Published: 5 Dec 2015
    5
    Medium

    CVE-2015-6388

    Last Modified: 12 Apr 2025

    Cisco Unified Computing System (UCS) Central software 1.3(0.1) allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted request, aka Bug ID CSCux33575.

    Published: 5 Dec 2015
    7.8
    High

    CVE-2015-6391

    Last Modified: 12 Apr 2025

    Cisco Unified SIP 3905 phones allow remote attackers to cause a denial of service (resource consumption and functionality loss) via a large amount of network traffic, aka Bug ID CSCuh51331.

    Published: 5 Dec 2015
    7.8
    High

    CVE-2015-6849

    Last Modified: 12 Apr 2025

    EMC NetWorker before 8.0.4.5, 8.1.x before 8.1.3.6, 8.2.x before 8.2.2.2, and 9.0 before build 407 allows remote attackers to cause a denial of service (process outage) via malformed RPC authentication messages.

    Published: 5 Dec 2015
    5
    Medium

    CVE-2015-1794

    Last Modified: 12 Apr 2025

    The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segmentation fault) via a zero p value in an anonymous Diffie-Hellman (DH) ServerKeyExchange message.

    Published: 4 Dec 2015
    6.7
    Medium

    CVE-2015-8660

    Last Modified: 12 Apr 2025

    The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.

    Published: 4 Dec 2015
    7.5
    High

    CVE-2015-0860

    Last Modified: 12 Apr 2025

    Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an "old-style" Debian binary package, which triggers a stack-based buffer overflow.

    Published: 3 Dec 2015
    7.5
    High

    CVE-2015-0859

    Last Modified: 12 Apr 2025

    The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes arguments to smokeping_cgi, which allows remote attackers to execute arbitrary code via crafted CGI arguments.

    Published: 3 Dec 2015
    7.2
    High

    CVE-2015-6383

    Last Modified: 12 Apr 2025

    Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license restrictions and obtain certain root privileges by using the CLI to enter crafted filenames, aka Bug ID CSCuv93130.

    Published: 3 Dec 2015
    4.3
    Medium

    CVE-2015-6390

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1.10) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCup92741.

    Published: 3 Dec 2015
    5.3
    Medium

    CVE-2015-3195

    Last Modified: 12 Apr 2025

    The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.

    Published: 3 Dec 2015
    8.6
    High

    CVE-2015-1142857

    Last Modified: 21 Nov 2024

    On multiple SR-IOV cars it is possible for VF's assigned to guests to send ethernet flow control pause frames via the PF. This includes Linux kernel ixgbe driver before commit f079fa005aae08ee0e1bc32699874ff4f02e11c1, the Linux Kernel i40e/i40evf driver before e7358f54a3954df16d4f87e3cad35063f1c17de5 and the DPDK before commit 3f12b9f23b6499ff66ec8b0de941fb469297e5d0, additionally Multiple vendor NIC firmware is affected.

    Published: 3 Dec 2015
    4.3
    Medium

    CVE-2015-3196

    Last Modified: 12 Apr 2025

    ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.

    Published: 3 Dec 2015
    6.5
    Medium

    CVE-2015-7514

    Last Modified: 20 Apr 2025

    OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.

    Published: 3 Dec 2015
    6.5
    Medium

    CVE-2015-8504

    Last Modified: 20 Apr 2025

    Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a client.

    Published: 3 Dec 2015
    7.5
    High

    CVE-2015-3193

    Last Modified: 12 Apr 2025

    The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for remote attackers to obtain sensitive private-key information via an attack against use of a (1) Diffie-Hellman (DH) or (2) Diffie-Hellman Ephemeral (DHE) ciphersuite.

    Published: 3 Dec 2015
    8.6
    High

    CVE-2015-8616

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the Collator::sortWithSortKeys function in ext/intl/collator/collator_sort.c in PHP 7.x before 7.0.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact by leveraging the relationships between a key buffer and a destroyed array.

    Published: 3 Dec 2015
    9.3
    Critical

    CVE-2015-8024

    Last Modified: 12 Apr 2025

    McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) 9.3.x before 9.3.2MR19, 9.4.x before 9.4.2MR9, and 9.5.x before 9.5.0MR8, when configured to use Active Directory or LDAP authentication sources, allow remote attackers to bypass authentication by logging in with the username "NGCP|NGCP|NGCP;" and any password.

    Published: 2 Dec 2015
    3.5
    Low

    CVE-2015-5304

    Last Modified: 12 Apr 2025

    Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the server, which allows remote authenticated users with the Monitor, Deployer, or Auditor role to cause a denial of service via unspecified vectors.

    Published: 2 Dec 2015
    7.7
    High

    CVE-2015-8567

    Last Modified: 20 Apr 2025

    Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).

    Published: 2 Dec 2015
    6.5
    Medium

    CVE-2015-8568

    Last Modified: 20 Apr 2025

    Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly.

    Published: 2 Dec 2015
    9.8
    Critical

    CVE-2015-8787

    Last Modified: 12 Apr 2025

    The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by sending certain IPv4 packets to an incompletely configured interface, a related issue to CVE-2003-1604.

    Published: 2 Dec 2015
    7.2
    High

    CVE-2015-6385

    Last Modified: 12 Apr 2025

    The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbitrary commands with root privileges by leveraging administrative access to enter crafted environment variables, aka Bug ID CSCux14943.

    Published: 1 Dec 2015
    5
    Medium

    CVE-2015-6386

    Last Modified: 12 Apr 2025

    The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 and 8.5.1-021 allows remote attackers to cause a denial of service (CPU consumption) via FTP sessions in which the control connection is ended after data transfer, aka Bug ID CSCut94150.

    Published: 1 Dec 2015
    10
    Critical

    CVE-2015-6765

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in content/browser/appcache/appcache_update_job.cc in Google Chrome before 47.0.2526.73 allows remote attackers to execute arbitrary code or cause a denial of service by leveraging the mishandling of AppCache update jobs.

    Published: 1 Dec 2015
    7.5
    High

    CVE-2015-6772

    Last Modified: 12 Apr 2025

    The DOM implementation in Blink, as used in Google Chrome before 47.0.2526.73, does not prevent javascript: URL navigation while a document is being detached, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that improperly interacts with a plugin.

    Published: 1 Dec 2015
    4.3
    Medium

    CVE-2015-6779

    Last Modified: 12 Apr 2025

    PDFium, as used in Google Chrome before 47.0.2526.73, does not properly restrict use of chrome: URLs, which allows remote attackers to bypass intended scheme restrictions via a crafted PDF document, as demonstrated by a document with a link to a chrome://settings URL.

    Published: 1 Dec 2015
    6.8
    Medium

    CVE-2015-6780

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the Infobars implementation in Google Chrome before 47.0.2526.73 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site, related to browser/ui/views/website_settings/website_settings_popup_view.cc.

    Published: 1 Dec 2015
    4.3
    Medium

    CVE-2015-6782

    Last Modified: 12 Apr 2025

    The Document::open function in WebKit/Source/core/dom/Document.cpp in Google Chrome before 47.0.2526.73 does not ensure that page-dismissal event handling is compatible with modal-dialog blocking, which makes it easier for remote attackers to spoof Omnibox content via a crafted web site.

    Published: 1 Dec 2015
    4.3
    Medium

    CVE-2015-6785

    Last Modified: 12 Apr 2025

    The CSPSource::hostMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts an x.y hostname as a match for a *.x.y pattern, which might allow remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a policy that was intended to be specific to subdomains.

    Published: 1 Dec 2015
    4.3
    Medium

    CVE-2015-6786

    Last Modified: 12 Apr 2025

    The CSPSourceList::matches function in WebKit/Source/core/frame/csp/CSPSourceList.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts a blob:, data:, or filesystem: URL as a match for a * pattern, which allows remote attackers to bypass intended scheme restrictions in opportunistic circumstances by leveraging a policy that relies on this pattern.

    Published: 1 Dec 2015
    7.5
    High

    CVE-2015-8479

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the AudioOutputDevice::OnDeviceAuthorized function in media/audio/audio_output_device.cc in Google Chrome before 47.0.2526.73 allows attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact by triggering access to an unauthorized audio output device.

    Published: 1 Dec 2015
    7.1
    High

    CVE-2015-5312

    Last Modified: 12 Apr 2025

    The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.

    Published: 1 Dec 2015
    7.5
    High

    CVE-2015-6773

    Last Modified: 12 Apr 2025

    The convolution implementation in Skia, as used in Google Chrome before 47.0.2526.73, does not properly constrain row lengths, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted graphics data.

    Published: 1 Dec 2015
    7.5
    High

    CVE-2015-6781

    Last Modified: 12 Apr 2025

    Integer overflow in the FontData::Bound function in data/font_data.cc in Google sfntly, as used in Google Chrome before 47.0.2526.73, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted offset or length value within font data in an SFNT container.

    Published: 1 Dec 2015
    10
    Critical

    CVE-2015-6787

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 1 Dec 2015
    5
    Medium

    CVE-2015-7497

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.

    Published: 1 Dec 2015
    5
    Medium

    CVE-2015-7499

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.

    Published: 1 Dec 2015
    5
    Medium

    CVE-2015-7500

    Last Modified: 12 Apr 2025

    The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.

    Published: 1 Dec 2015