CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2015-5019

    Last Modified: 12 Apr 2025

    IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated users to read or upload files by leveraging a password-change requirement.

    Published: 8 Nov 2015
    2.6
    Low

    CVE-2015-7412

    Last Modified: 12 Apr 2025

    The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain plaintext data via a padding-oracle attack.

    Published: 8 Nov 2015
    5
    Medium

    CVE-2015-1994

    Last Modified: 12 Apr 2025

    IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

    Published: 8 Nov 2015
    4.3
    Medium

    CVE-2015-4928

    Last Modified: 12 Apr 2025

    Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, includes cleartext passwords on a Configs screen, which allows physically proximate attackers to obtain sensitive information by reading password fields.

    Published: 8 Nov 2015
    7.5
    High

    CVE-2015-4963

    Last Modified: 12 Apr 2025

    IBM Security Access Manager for Web 7.x before 7.0.0.16 and 8.x before 8.0.1.3 mishandles WebSEAL HTTPTransformation requests, which allows remote attackers to read or write to arbitrary files via unspecified vectors.

    Published: 8 Nov 2015
    6.5
    Medium

    CVE-2015-4966

    Last Modified: 12 Apr 2025

    IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7.6.0.2 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 FP009, 7.5.1, and 7.6.0 before 7.6.0.2 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products have a default administrator account, which makes it easier for remote authenticated users to obtain access via unspecified vectors.

    Published: 8 Nov 2015
    8.5
    High

    CVE-2015-5005

    Last Modified: 12 Apr 2025

    CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by leveraging presence on the cluster-wide password-change list.

    Published: 8 Nov 2015
    5
    Medium

    CVE-2015-5015

    Last Modified: 12 Apr 2025

    IBM WebSphere Commerce Enterprise 7.0.0.9 and 8.x before Feature Pack 8 allows remote attackers to obtain sensitive information via a crafted REST URL.

    Published: 8 Nov 2015
    7.2
    High

    CVE-2015-5043

    Last Modified: 12 Apr 2025

    diag in IBM Security Guardium 8.2 before p6015, 9.0 before p6015, 9.1, 9.5, and 10.0 before p6015 allows local users to obtain root access via unspecified key sequences.

    Published: 8 Nov 2015
    3.3
    Low

    CVE-2015-5044

    Last Modified: 12 Apr 2025

    The Flow Collector in IBM Security QRadar QFLOW 7.1.x before 7.1 MR2 Patch 11 IF3 and 7.2.x before 7.2.5 Patch 4 IF3 allows remote attackers to cause a denial of service via unspecified packets.

    Published: 8 Nov 2015
    6.5
    Medium

    CVE-2015-1989

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 8 Nov 2015
    4.3
    Medium

    CVE-2015-1995

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 8 Nov 2015
    2.1
    Low

    CVE-2015-1996

    Last Modified: 12 Apr 2025

    IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.

    Published: 8 Nov 2015
    6.8
    Medium

    CVE-2015-1997

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar Vulnerability Manager 7.2.x before 7.2.5 Patch 5 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 8 Nov 2015
    5
    Medium

    CVE-2015-1999

    Last Modified: 12 Apr 2025

    IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 places session IDs in https URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

    Published: 8 Nov 2015
    4.3
    Medium

    CVE-2015-2017

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

    Published: 8 Nov 2015
    4
    Medium

    CVE-2015-7395

    Last Modified: 12 Apr 2025

    IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 FP002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2 FP002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended work-order change restrictions via unspecified vectors.

    Published: 8 Nov 2015
    10
    Critical

    CVE-2015-6476

    Last Modified: 12 Apr 2025

    Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 have hardcoded SSH keys, which makes it easier for remote attackers to obtain access via an SSH session.

    Published: 7 Nov 2015
    5
    Medium

    CVE-2015-7254

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI.

    Published: 7 Nov 2015
    5
    Medium

    CVE-2015-7762

    Last Modified: 12 Apr 2025

    rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conducting a replay attack or (2) sniffing the network.

    Published: 6 Nov 2015
    5
    Medium

    CVE-2015-7763

    Last Modified: 12 Apr 2025

    rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conducting a replay attack or (2) sniffing the network.

    Published: 6 Nov 2015
    6.8
    Medium

    CVE-2015-7809

    Last Modified: 12 Apr 2025

    The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.

    Published: 6 Nov 2015
    5
    Medium

    CVE-2015-8081

    Last Modified: 12 Apr 2025

    The Field as Block module 7.x-1.x before 7.x-1.4 for Drupal might allow remote attackers to obtain sensitive field information by reading a cached block.

    Published: 6 Nov 2015
    7.5
    High

    CVE-2015-8082

    Last Modified: 12 Apr 2025

    The Login Disable module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly load the user_logout function, which allows remote attackers to bypass the logout protection mechanism by leveraging a contributed user authentication module, as demonstrated by the CAS and URL Login modules.

    Published: 6 Nov 2015
    6.1
    Medium

    CVE-2015-6546

    Last Modified: 12 Apr 2025

    The vCMP host in F5 BIG-IP Analytics, APM, ASM, GTM, Link Controller, and LTM 11.0.0 before 11.6.0, BIG-IP AAM 11.4.0 before 11.6.0, BIG-IP AFM and PEM 11.3.0 before 11.6.0, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.0.0 through 11.3.0, BIG-IP PSM 11.0.0 through 11.4.1 allows remote attackers to cause a denial of service via "malicious traffic."

    Published: 6 Nov 2015
    9
    Critical

    CVE-2015-7394

    Last Modified: 12 Apr 2025

    The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP AFM, PEM 11.3.0 before 12.0.0, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.1.0 through 11.3.0, BIG-IP GTM 11.1.0 through 11.6.0, BIG-IP PSM 11.1.0 through 11.4.1, BIG-IQ Cloud and Security 4.0.0 through 4.5.0, BIG-IQ Device 4.2.0 through 4.5.0, BIG-IQ ADC 4.5.0, and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to cause a denial of service or gain privileges by leveraging permission to upload and execute code.

    Published: 6 Nov 2015
    5
    Medium

    CVE-2015-7770

    Last Modified: 12 Apr 2025

    Dell SonicWall TotalSecure TZ 100 devices with firmware before 5.9.1.0-22o allow remote attackers to cause a denial of service via a crafted packet.

    Published: 6 Nov 2015
    7.8
    High

    CVE-2015-6292

    Last Modified: 12 Apr 2025

    The proxy-cache implementation in Cisco AsyncOS 8.0.x before 8.0.7-151, 8.1.x and 8.5.x before 8.5.2-004, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via multiple proxy connections, aka Bug ID CSCus10922.

    Published: 6 Nov 2015
    6.9
    Medium

    CVE-2015-4282

    Last Modified: 12 Apr 2025

    Cisco Mobility Services Engine (MSE) through 8.0.120.7 uses weak permissions for unspecified binary files, which allows local users to obtain root privileges by writing to a file, aka Bug ID CSCuv40504.

    Published: 6 Nov 2015
    10
    Critical

    CVE-2015-5672

    Last Modified: 12 Apr 2025

    TYPE-MOON Fate/stay night, Fate/hollow ataraxia, Witch on the Holy Night, and Fate/stay night + hollow ataraxia set allow remote attackers to execute arbitrary OS commands via crafted saved data.

    Published: 6 Nov 2015
    9
    Critical

    CVE-2015-6298

    Last Modified: 12 Apr 2025

    The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote authenticated users to obtain root privileges via crafted certificate-generation arguments, aka Bug ID CSCus83445.

    Published: 6 Nov 2015
    6.5
    Medium

    CVE-2015-6316

    Last Modified: 12 Apr 2025

    The default configuration of sshd_config in Cisco Mobility Services Engine (MSE) through 8.0.120.7 allows logins by the oracle account, which makes it easier for remote attackers to obtain access by entering this account's hardcoded password in an SSH session, aka Bug ID CSCuv40501.

    Published: 6 Nov 2015
    7.8
    High

    CVE-2015-6291

    Last Modified: 12 Apr 2025

    Cisco AsyncOS before 8.5.7-043, 9.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malformed fields during body-contains, attachment-contains, every-attachment-contains, attachment-binary-contains, dictionary-match, and attachment-dictionary-match filtering, which allows remote attackers to cause a denial of service (memory consumption) via a crafted attachment in an e-mail message, aka Bug ID CSCuv47151.

    Published: 6 Nov 2015
    7.8
    High

    CVE-2015-6293

    Last Modified: 12 Apr 2025

    Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via multiple file-range requests, aka Bug ID CSCur39155.

    Published: 6 Nov 2015
    7.8
    High

    CVE-2015-6321

    Last Modified: 12 Apr 2025

    Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) devices; before 9.1.0-032, 9.1.1 before 9.1.1-005, and 9.5.x before 9.5.0-025 on Content Security Management Appliance (SMA) devices; and before 7.7.0-725 and 8.x before 8.0.8-113 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets, aka Bug IDs CSCus79774, CSCus79777, and CSCzv95795.

    Published: 6 Nov 2015
    9.8
    Critical

    CVE-2015-7501

    Last Modified: 20 Apr 2025

    Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

    Published: 6 Nov 2015
    9.8
    Critical

    CVE-2015-5344

    Last Modified: 12 Apr 2025

    The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via a crafted serialized Java object in an HTTP request.

    Published: 6 Nov 2015
    7.5
    High

    CVE-2015-8080

    Last Modified: 12 Apr 2025

    Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow.

    Published: 6 Nov 2015
    4.3
    Medium

    CVE-2015-7185

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which allows remote attackers to spoof the address bar via crafted JavaScript code.

    Published: 5 Nov 2015
    4.3
    Medium

    CVE-2015-7186

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigger (1) a download or (2) cached profile-data reading via a file: URL in a saved HTML document.

    Published: 5 Nov 2015
    5
    Medium

    CVE-2015-7190

    Last Modified: 12 Apr 2025

    The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access this URL in a privileged context in conjunction with the crash reporter, which allows attackers to read log files and visit file: URLs of HTML documents via a crafted application.

    Published: 5 Nov 2015
    4.3
    Medium

    CVE-2015-7191

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 42.0 on Android improperly restricts URL strings in intents, which allows attackers to conduct cross-site scripting (XSS) attacks via vectors involving an intent: URL and fallback navigation, aka "Universal XSS (UXSS)."

    Published: 5 Nov 2015
    7.5
    High

    CVE-2015-7192

    Last Modified: 12 Apr 2025

    The accessibility-tools feature in Mozilla Firefox before 42.0 on OS X improperly interacts with the implementation of the TABLE element, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using an NSAccessibilityIndexAttribute value to reference a row index.

    Published: 5 Nov 2015
    7.5
    High

    CVE-2015-6867

    Last Modified: 19 Nov 2025

    The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to execute arbitrary commands via a crafted packet, aka ZDI-CAN-2914.

    Published: 4 Nov 2015
    6.8
    Medium

    CVE-2015-2902

    Last Modified: 12 Apr 2025

    HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate.

    Published: 4 Nov 2015
    6.9
    Medium

    CVE-2015-2903

    Last Modified: 12 Apr 2025

    The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password.

    Published: 4 Nov 2015
    5
    Medium

    CVE-2015-6029

    Last Modified: 12 Apr 2025

    HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.

    Published: 4 Nov 2015
    7.2
    High

    CVE-2015-4927

    Last Modified: 12 Apr 2025

    The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses world-writable permissions for unspecified files, which allows local users to gain privileges by writing to a file.

    Published: 4 Nov 2015
    5.5
    Medium

    CVE-2015-5021

    Last Modified: 12 Apr 2025

    IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors.

    Published: 4 Nov 2015
    7.2
    High

    CVE-2015-6030

    Last Modified: 12 Apr 2025

    HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.

    Published: 4 Nov 2015