CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-6492

    Last Modified: 3 Jun 2026

    Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote attackers to cause a denial of service (memory corruption and device crash) via a crafted HTTP request.

    Published: 28 Oct 2015
    9.8
    Critical

    CVE-2015-6490

    Last Modified: 3 Jun 2026

    Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 28 Oct 2015
    10
    Critical

    CVE-2015-3972

    Last Modified: 12 Apr 2025

    The web interface on Janitza UMG 508, 509, 511, 604, and 605 devices supports only short PIN values for authentication, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 28 Oct 2015
    4.3
    Medium

    CVE-2015-6488

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web server on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Oct 2015
    5
    Medium

    CVE-2015-3973

    Last Modified: 12 Apr 2025

    Janitza UMG 508, 509, 511, 604, and 605 devices improperly generate session tokens, which makes it easier for remote attackers to determine a PIN value via unspecified computations on session-token values.

    Published: 28 Oct 2015
    6.5
    Medium

    CVE-2015-7904

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary JSP code via vectors involving an upload of an image file.

    Published: 28 Oct 2015
    6.8
    Medium

    CVE-2015-3967

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605 devices allows remote attackers to hijack the authentication of arbitrary users.

    Published: 28 Oct 2015
    7.5
    High

    CVE-2015-3968

    Last Modified: 12 Apr 2025

    The FTP service on Janitza UMG 508, 509, 511, 604, and 605 devices has a default password, which makes it easier for remote attackers to read or write to files via a session on TCP port 21.

    Published: 28 Oct 2015
    5
    Medium

    CVE-2015-3969

    Last Modified: 12 Apr 2025

    Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection information via a request to UDP port (1) 1234 or (2) 1235.

    Published: 28 Oct 2015
    4.3
    Medium

    CVE-2015-3970

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Oct 2015
    7.5
    High

    CVE-2015-3971

    Last Modified: 12 Apr 2025

    The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows remote attackers to read or write to files, or execute arbitrary JASIC code, via a session on TCP port 1239.

    Published: 28 Oct 2015
    4
    Medium

    CVE-2015-5712

    Last Modified: 12 Apr 2025

    Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote authenticated users to obtain sensitive system information by visiting an unspecified URL.

    Published: 28 Oct 2015
    5
    Medium

    CVE-2015-5713

    Last Modified: 12 Apr 2025

    Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote attackers to obtain sensitive log information by visiting an unspecified URL.

    Published: 28 Oct 2015
    6.5
    Medium

    CVE-2015-6486

    Last Modified: 12 Apr 2025

    SQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Oct 2015
    4
    Medium

    CVE-2015-6491

    Last Modified: 12 Apr 2025

    Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote authenticated users to insert the content of an arbitrary file into a FRAME element via unspecified vectors.

    Published: 28 Oct 2015
    6.8
    Medium

    CVE-2015-6493

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

    Published: 28 Oct 2015
    3.5
    Low

    CVE-2015-6494

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Oct 2015
    3.3
    Low

    CVE-2015-7836

    Last Modified: 12 Apr 2025

    Siemens RUGGEDCOM ROS before 4.2.1 allows remote attackers to obtain sensitive information by sniffing the network for VLAN data within the padding section of an Ethernet frame.

    Published: 28 Oct 2015
    5
    Medium

    CVE-2015-7873

    Last Modified: 12 Apr 2025

    The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.

    Published: 28 Oct 2015
    4.3
    Medium

    CVE-2015-7900

    Last Modified: 12 Apr 2025

    Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive debugging information by entering a crafted URL to trigger an exception, and then visiting a certain status page.

    Published: 28 Oct 2015
    6.5
    Medium

    CVE-2015-7901

    Last Modified: 12 Apr 2025

    Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

    Published: 28 Oct 2015
    5
    Medium

    CVE-2015-7902

    Last Modified: 12 Apr 2025

    Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed login attempts in unspecified circumstances, which allows remote attackers to obtain sensitive information via a series of requests.

    Published: 28 Oct 2015
    6.5
    Medium

    CVE-2015-7903

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Oct 2015
    4.3
    Medium

    CVE-2015-3996

    Last Modified: 12 Apr 2025

    The default AFSecurityPolicy.validatesDomainName configuration for AFSSLPinningModeNone in the AFNetworking framework before 2.5.3, as used in the ownCloud iOS Library, disables verification of a server hostname against the domain name in the subject's Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 27 Oct 2015
    7.5
    High

    CVE-2015-7986

    Last Modified: 12 Apr 2025

    The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTTP request, aka SAP Security Note 2197428.

    Published: 27 Oct 2015
    5.1
    Medium

    CVE-2015-5665

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijack the authentication of arbitrary users for requests that write to PHP scripts, related to the doValidToken function.

    Published: 27 Oct 2015
    5
    Medium

    CVE-2015-6340

    Last Modified: 12 Apr 2025

    The Proxy Mobile IPv6 (PMIPv6) component in the CDMA implementation on Cisco ASR 5000 devices with software 19.0.M0.60737 allows remote attackers to cause a denial of service (hamgr process restart) via a crafted header in a PMIPv6 packet, aka Bug ID CSCuv63280.

    Published: 27 Oct 2015
    7.8
    High

    CVE-2015-8019

    Last Modified: 12 Apr 2025

    The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a write system call followed by a recvmsg system call.

    Published: 27 Oct 2015
    6.4
    Medium

    CVE-2015-5305

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handled before passing it to etcd.

    Published: 27 Oct 2015
    5.8
    Medium

    CVE-2014-8242

    Last Modified: 12 Apr 2025

    librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birthday attack.

    Published: 26 Oct 2015
    9
    Critical

    CVE-2015-7699

    Last Modified: 12 Apr 2025

    The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instantiate arbitrary classes and possibly execute arbitrary code via a crafted mount point option, related to "objectstore."

    Published: 26 Oct 2015
    2.6
    Low

    CVE-2015-4456

    Last Modified: 12 Apr 2025

    ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which allows man-in-the-middle attackers to bypass the user's certificate distrust decision and obtain sensitive information by leveraging a self-signed certificate and a connection to a server using its own self-signed certificate.

    Published: 26 Oct 2015
    7.5
    High

    CVE-2015-6500

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory contents and possibly cause a denial of service (CPU consumption) via a .. (dot dot) in the dir parameter to index.php/apps/files/ajax/scan.php.

    Published: 26 Oct 2015
    4
    Medium

    CVE-2015-6670

    Last Modified: 12 Apr 2025

    ownCloud Server before 7.0.8, 8.0.x before 8.0.6, and 8.1.x before 8.1.1 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to apps/calendar/export.php.

    Published: 26 Oct 2015
    5.1
    Medium

    CVE-2015-7298

    Last Modified: 12 Apr 2025

    ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which makes it easier for remote attackers to conduct man-in-the-middle (MITM) attacks by leveraging a server using a self-signed certificate. NOTE: this vulnerability exists because of a partial CVE-2015-4456 regression.

    Published: 26 Oct 2015
    3.5
    Low

    CVE-2015-7881

    Last Modified: 12 Apr 2025

    The Colorbox module 7.x-2.x before 7.x-2.10 for Drupal allows remote authenticated users with certain permissions to bypass intended access restrictions and "add unexpected content to a Colorbox" via unspecified vectors, possibly related to a link in a comment.

    Published: 26 Oct 2015
    7.2
    High

    CVE-2015-4974

    Last Modified: 12 Apr 2025

    IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors.

    Published: 26 Oct 2015
    2.1
    Low

    CVE-2015-4981

    Last Modified: 12 Apr 2025

    IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory via unspecified vectors.

    Published: 26 Oct 2015
    3.2
    Low

    CVE-2015-5011

    Last Modified: 12 Apr 2025

    IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.

    Published: 26 Oct 2015
    9.3
    Critical

    CVE-2015-5014

    Last Modified: 12 Apr 2025

    IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an executable file during a client upload operation.

    Published: 26 Oct 2015
    2.1
    Low

    CVE-2015-5448

    Last Modified: 12 Apr 2025

    HP Asset Manager 9.40 and 9.41 before 9.41.11103 P4-rev1 and 9.50 before 9.50.11925 P3 allows local users to obtain sensitive information via unspecified vectors.

    Published: 26 Oct 2015
    7.5
    High

    CVE-2015-8077

    Last Modified: 12 Apr 2025

    Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the start_octet variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.

    Published: 26 Oct 2015
    7.5
    High

    CVE-2015-8078

    Last Modified: 12 Apr 2025

    Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified impact via vectors related to urlfetch range checks and the section_offset variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8076.

    Published: 26 Oct 2015
    9
    Critical

    CVE-2015-6335

    Last Modified: 12 Apr 2025

    The policy implementation in Cisco FireSIGHT Management Center 5.3.1.7, 5.4.0.4, and 6.0.0 for VMware allows remote authenticated administrators to bypass intended policy restrictions and execute Linux commands as root via unspecified vectors, aka Bug ID CSCuw12839.

    Published: 25 Oct 2015
    2.1
    Low

    CVE-2015-1005

    Last Modified: 12 Apr 2025

    IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.

    Published: 25 Oct 2015
    7.1
    High

    CVE-2015-6325

    Last Modified: 12 Apr 2025

    Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.4), 9.2 before 9.2(4), 9.3 before 9.3(3.1), and 9.4 before 9.4(1.1) allows remote attackers to cause a denial of service (device reload) via a crafted DNS response, aka Bug ID CSCut03495.

    Published: 25 Oct 2015
    7.8
    High

    CVE-2015-6326

    Last Modified: 12 Apr 2025

    Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.6), 9.2 before 9.2(4), 9.3 before 9.3(3.5), and 9.4 before 9.4(1.5) allows remote attackers to cause a denial of service (device reload) via a crafted DNS response, aka Bug ID CSCuu07799.

    Published: 25 Oct 2015
    10
    Critical

    CVE-2015-1001

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in IniNet embeddedWebServer (aka eWebServer) before 2.02 allow remote attackers to execute arbitrary code via a long field in an HTTP request.

    Published: 25 Oct 2015
    6.4
    Medium

    CVE-2015-1002

    Last Modified: 12 Apr 2025

    IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string.

    Published: 25 Oct 2015
    5
    Medium

    CVE-2015-1003

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname.

    Published: 25 Oct 2015