CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2015-7771

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted SSID that is encountered by an applican application, a different vulnerability than CVE-2015-7772.

    Published: 20 Nov 2015
    4.3
    Medium

    CVE-2015-7772

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers WebView anchor attachment in an applican application, a different vulnerability than CVE-2015-7771.

    Published: 20 Nov 2015
    6.5
    Medium

    CVE-2015-7773

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the Panel component in Bastian Allgeier Kirby before 2.1.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file that lacks an extension, and then renaming this file to have a .php extension.

    Published: 20 Nov 2015
    6.5
    Medium

    CVE-2015-8345

    Last Modified: 20 Apr 2025

    The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash and infinite loop) via vectors involving the command block list.

    Published: 20 Nov 2015
    5.3
    Medium

    CVE-2015-9019

    Last Modified: 20 Apr 2025

    In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.

    Published: 20 Nov 2015
    3.6
    Low

    CVE-2015-0794

    Last Modified: 12 Apr 2025

    modules.d/90crypt/module-setup.sh in the dracut package before 037-17.30.1 in openSUSE 13.2 allows local users to have unspecified impact via a symlink attack on /tmp/dracut_block_uuid.map.

    Published: 19 Nov 2015
    5
    Medium

    CVE-2015-7845

    Last Modified: 12 Apr 2025

    The exception handling mechanism in the CLI Module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways with software before V100R001C20SPH605 allows remote attackers to cause a denial of service (CLI outage) via crafted SSH packets.

    Published: 19 Nov 2015
    6.8
    Medium

    CVE-2015-7984

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary (1) commands via the cmd parameter to admin/cmdshell.php, (2) SQL queries via the sql parameter to admin/sqlshell.php, or (3) PHP code via the php parameter to admin/phpshell.php.

    Published: 19 Nov 2015
    4.3
    Medium

    CVE-2015-7385

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Open-Xchange OX Guard before 2.0.0-rev11 allows remote attackers to inject arbitrary web script or HTML via the uid field in a PGP public key, which is not properly handled in "Guard PGP Settings."

    Published: 19 Nov 2015
    7.8
    High

    CVE-2015-8083

    Last Modified: 12 Apr 2025

    An unspecified module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways with software before V200R003C00SPC300 does not properly initialize memory when processing timeout messages, which allows remote attackers to cause a denial of service (out-of-bounds memory access and device restart) via unknown vectors.

    Published: 19 Nov 2015
    5
    Medium

    CVE-2015-8087

    Last Modified: 12 Apr 2025

    Huawei NE20E-S, NE40E-M, and NE40E-M2 routers with software before V800R007C10SPC100 and NE40E and NE80E routers with software before V800R007C00SPC100 allows remote attackers to send packets to other VPNs and conduct flooding attacks via a crafted MPLS forwarding packet, aka a "VPN routing and forwarding (VRF) hopping vulnerability."

    Published: 19 Nov 2015
    10
    Critical

    CVE-2015-8236

    Last Modified: 12 Apr 2025

    Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to execute arbitrary code as root by leveraging management-plane access, aka Bug 138716.

    Published: 19 Nov 2015
    4.3
    Medium

    CVE-2015-4112

    Last Modified: 12 Apr 2025

    The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site, related to a "cross frame scripting" issue.

    Published: 19 Nov 2015
    7.8
    High

    CVE-2015-7910

    Last Modified: 12 Apr 2025

    Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass intended access restrictions by disregarding this header and processing the response body.

    Published: 19 Nov 2015
    4.3
    Medium

    CVE-2015-6374

    Last Modified: 12 Apr 2025

    The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, aka Bug ID CSCux10604.

    Published: 19 Nov 2015
    5
    Medium

    CVE-2015-6368

    Last Modified: 12 Apr 2025

    Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608.

    Published: 19 Nov 2015
    4.9
    Medium

    CVE-2015-6369

    Last Modified: 12 Apr 2025

    The USB driver in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows physically proximate attackers to cause a denial of service via a crafted USB device that triggers invalid USB commands, aka Bug ID CSCux10531.

    Published: 19 Nov 2015
    7.2
    High

    CVE-2015-6370

    Last Modified: 12 Apr 2025

    The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows local users to execute arbitrary OS commands as root via crafted CLI input, aka Bug ID CSCux10578.

    Published: 19 Nov 2015
    4
    Medium

    CVE-2015-6371

    Last Modified: 12 Apr 2025

    Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621.

    Published: 19 Nov 2015
    4.3
    Medium

    CVE-2015-5255

    Last Modified: 12 Apr 2025

    Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.

    Published: 18 Nov 2015
    4.3
    Medium

    CVE-2015-8052

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8053.

    Published: 18 Nov 2015
    4
    Medium

    CVE-2015-8090

    Last Modified: 12 Apr 2025

    The Web Server component in TIBCO LogLogic Unity before 1.1.1 allows remote authenticated users to gain privileges, and consequently obtain sensitive information, via an HTTP request.

    Published: 18 Nov 2015
    10
    Critical

    CVE-2015-8051

    Last Modified: 12 Apr 2025

    The Adobe Premiere Clip app before 1.2.1 for iOS mishandles unspecified input, which has unknown impact and attack vectors.

    Published: 18 Nov 2015
    4.3
    Medium

    CVE-2015-8053

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8052.

    Published: 18 Nov 2015
    6.8
    Medium

    CVE-2015-5999

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) change the network policy, or (3) possibly have other unspecified impact via crafted requests to hedwig.cgi and pigwidgeon.cgi.

    Published: 18 Nov 2015
    9.8
    Critical

    CVE-2015-4852

    Last Modified: 21 Apr 2026

    The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the scope of this CVE is limited to the WebLogic Server product.

    Published: 18 Nov 2015
    4.3
    Medium

    CVE-2015-6372

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCux10614.

    Published: 18 Nov 2015
    6.8
    Medium

    CVE-2015-6373

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCux10611.

    Published: 18 Nov 2015
    6.8
    Medium

    CVE-2015-6330

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cisco Prime Collaboration Assurance 10.5(1) and 10.6 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus62712.

    Published: 18 Nov 2015
    6.8
    Medium

    CVE-2015-6357

    Last Modified: 12 Apr 2025

    The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid package, and consequently execute arbitrary code, via a crafted certificate, aka Bug ID CSCuw06444.

    Published: 18 Nov 2015
    2.1
    Low

    CVE-2015-6847

    Last Modified: 12 Apr 2025

    The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 before P3 stores cleartext NAVISPHERE GUI passwords in a log file, which allows local users to obtain sensitive information by reading this file.

    Published: 18 Nov 2015
    8.8
    High

    CVE-2016-1841

    Last Modified: 12 Apr 2025

    libxslt, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 18 Nov 2015
    5.1
    Medium

    CVE-2015-7502

    Last Modified: 12 Apr 2025

    Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive data and consequently gain privileges by leveraging access to (1) database exports or (2) log files.

    Published: 18 Nov 2015
    6.8
    Medium

    CVE-2015-8131

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x before 4.2.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 18 Nov 2015
    5.5
    Medium

    CVE-2015-8234

    Last Modified: 20 Apr 2025

    The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.

    Published: 18 Nov 2015
    4.3
    Medium

    CVE-2015-7997

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Nov 2015
    5
    Medium

    CVE-2015-5311

    Last Modified: 12 Apr 2025

    PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.

    Published: 17 Nov 2015
    5
    Medium

    CVE-2015-7998

    Last Modified: 12 Apr 2025

    The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allows attackers to obtain sensitive information via unspecified vectors.

    Published: 17 Nov 2015
    7.5
    High

    CVE-2015-8220

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link.

    Published: 17 Nov 2015
    5
    Medium

    CVE-2015-7996

    Last Modified: 12 Apr 2025

    The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow attackers to obtain credentials via the browser cache.

    Published: 17 Nov 2015
    10
    Critical

    CVE-2015-8221

    Last Modified: 12 Apr 2025

    Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, which triggers a heap-based buffer overflow.

    Published: 17 Nov 2015
    4.6
    Medium

    CVE-2015-8222

    Last Modified: 12 Apr 2025

    The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.

    Published: 17 Nov 2015
    4.3
    Medium

    CVE-2015-8232

    Last Modified: 12 Apr 2025

    The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstances, which might allow remote attackers to obtain sensitive information from the anonymous user profile via unspecified vectors.

    Published: 17 Nov 2015
    2.6
    Low

    CVE-2015-8233

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.6 for Drupal allows remote administrators with the "Administer themes" permission to inject arbitrary web script or HTML via unspecified vectors related to theme settings.

    Published: 17 Nov 2015
    7.5
    High

    CVE-2015-8219

    Last Modified: 12 Apr 2025

    The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-value constraints on tile coordinates, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data.

    Published: 17 Nov 2015
    7.5
    High

    CVE-2015-8216

    Last Modified: 12 Apr 2025

    The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8.2 omits certain width and height checks, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted MJPEG data.

    Published: 17 Nov 2015
    7.5
    High

    CVE-2015-8217

    Last Modified: 12 Apr 2025

    The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indicator, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted High Efficiency Video Coding (HEVC) data.

    Published: 17 Nov 2015
    6.8
    Medium

    CVE-2015-8218

    Last Modified: 12 Apr 2025

    The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted CCITT FAX data.

    Published: 17 Nov 2015
    2.6
    Low

    CVE-2015-5281

    Last Modified: 12 Apr 2025

    The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.

    Published: 17 Nov 2015
    7.5
    High

    CVE-2015-7816

    Last Modified: 12 Apr 2025

    The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection attacks, conduct Server-Side Request Forgery (SSRF) attacks, and execute arbitrary PHP code via a crafted HTTP header.

    Published: 16 Nov 2015