CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-4795

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Utilities Work and Asset Management component in Oracle Industry Applications 1.9.1.1.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Add-On Applications.

    Published: 21 Oct 2015
    9
    Critical

    CVE-2015-4796

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-4888.

    Published: 21 Oct 2015
    2.1
    Low

    CVE-2015-4801

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality via unknown vectors related to Solaris Kernel Zones.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4804

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Management component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.

    Published: 21 Oct 2015
    9
    Critical

    CVE-2015-7698

    Last Modified: 12 Apr 2025

    icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argument in the (1) listShares function in Server.php or the (2) connect or (3) read function in Share.php.

    Published: 21 Oct 2015
    10
    Critical

    CVE-2015-4716

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the application or execute arbitrary code via unspecified vectors.

    Published: 21 Oct 2015
    7.8
    High

    CVE-2015-4717

    Last Modified: 12 Apr 2025

    The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names.

    Published: 21 Oct 2015
    9
    Critical

    CVE-2015-4718

    Last Modified: 12 Apr 2025

    The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via a ; (semicolon) character in a file.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-5954

    Last Modified: 12 Apr 2025

    The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0.5 does not consider that NULL is a valid getPath return value, which allows remote authenticated users to bypass intended access restrictions and gain access to users files via a sharing link to a file with a deleted parent folder.

    Published: 21 Oct 2015
    7.5
    High

    CVE-2015-7299

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter.

    Published: 21 Oct 2015
    3.5
    Low

    CVE-2015-5953

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the activity application in ownCloud Server before 7.0.5 and 8.0.x before 8.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a " (double quote) character in a filename in a shared folder.

    Published: 21 Oct 2015
    5
    Medium

    CVE-2015-7822

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Kentico CMS 8.2 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter name to CMSModules/AdminControls/Pages/UIPage.aspx or the (2) CMSBodyClass cookie variable to the default URI.

    Published: 21 Oct 2015
    5.8
    Medium

    CVE-2015-7823

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in CMSPages/GetDocLink.ashx in Kentico CMS 8.2 through 8.2.41 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the link parameter.

    Published: 21 Oct 2015
    7.5
    High

    CVE-2015-7876

    Last Modified: 12 Apr 2025

    The escapeLike function in sqlsrv/database.inc in the Drupal 7 driver for SQL Server and SQL Azure 7.x-1.x before 7.x-1.4 does not properly escape certain characters, which allows remote attackers to execute arbitrary SQL commands via vectors involving a module using the db_like function.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4802

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4792.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4833

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4866

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.

    Published: 21 Oct 2015
    3.5
    Low

    CVE-2015-4890

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Replication.

    Published: 21 Oct 2015
    7.5
    High

    CVE-2015-7704

    Last Modified: 20 Apr 2025

    The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.

    Published: 21 Oct 2015
    6.5
    Medium

    CVE-2015-7855

    Last Modified: 20 Apr 2025

    The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value.

    Published: 21 Oct 2015
    9.8
    Critical

    CVE-2015-7871

    Last Modified: 20 Apr 2025

    Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.

    Published: 21 Oct 2015
    3.5
    Low

    CVE-2015-4791

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Privileges.

    Published: 21 Oct 2015
    3.5
    Low

    CVE-2015-4807

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier, when running on Windows, allows remote authenticated users to affect availability via unknown vectors related to Server : Query Cache.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4815

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DDL.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4816

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.

    Published: 21 Oct 2015
    7.2
    High

    CVE-2015-4819

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client programs.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4826

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Types.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4830

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.

    Published: 21 Oct 2015
    2.8
    Low

    CVE-2015-4836

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : SP.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4858

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2015-4913.

    Published: 21 Oct 2015
    3.5
    Low

    CVE-2015-4861

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4862

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to DML.

    Published: 21 Oct 2015
    3.5
    Low

    CVE-2015-4864

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4870

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.

    Published: 21 Oct 2015
    4.6
    Medium

    CVE-2015-4879

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to DML.

    Published: 21 Oct 2015
    3.5
    Low

    CVE-2015-4895

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4904

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to libmysqld.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4905

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML.

    Published: 21 Oct 2015
    2.1
    Low

    CVE-2015-4910

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Memcached.

    Published: 21 Oct 2015
    3.5
    Low

    CVE-2015-4913

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.

    Published: 21 Oct 2015
    7.5
    High

    CVE-2015-5300

    Last Modified: 20 Apr 2025

    The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).

    Published: 21 Oct 2015
    7.5
    High

    CVE-2015-7691

    Last Modified: 20 Apr 2025

    The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.

    Published: 21 Oct 2015
    7.5
    High

    CVE-2015-7701

    Last Modified: 20 Apr 2025

    Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (memory consumption).

    Published: 21 Oct 2015
    9.8
    Critical

    CVE-2015-7705

    Last Modified: 20 Apr 2025

    The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.

    Published: 21 Oct 2015
    7.5
    High

    CVE-2015-7848

    Last Modified: 23 May 2025

    An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authentication code and a valid timestamp. When processed by the NTP daemon, it leads to an immediate crash.

    Published: 21 Oct 2015
    9.8
    Critical

    CVE-2015-7853

    Last Modified: 20 Apr 2025

    The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative input value.

    Published: 21 Oct 2015
    8.8
    High

    CVE-2015-7854

    Last Modified: 20 Apr 2025

    Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted key file.

    Published: 21 Oct 2015
    9.1
    Critical

    CVE-2016-5114

    Last Modified: 12 Apr 2025

    sapi/fpm/fpm/fpm_log.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 misinterprets the semantics of the snprintf return value, which allows attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and buffer overflow) via a long string, as demonstrated by a long URI in a configuration with custom REQUEST_URI logging.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4730

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.20 and earlier allows remote authenticated users to affect availability via unknown vectors related to Types.

    Published: 21 Oct 2015
    1.9
    Low

    CVE-2015-4766

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows local users to affect availability via unknown vectors related to Server : Security : Firewall.

    Published: 21 Oct 2015