CVE Feed

    Dashboard / CVE

    1.7
    Low

    CVE-2015-4792

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4802.

    Published: 21 Oct 2015
    4
    Medium

    CVE-2015-4800

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.

    Published: 21 Oct 2015
    7.5
    High

    CVE-2015-7692

    Last Modified: 20 Apr 2025

    The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.

    Published: 21 Oct 2015
    6.5
    Medium

    CVE-2015-7702

    Last Modified: 20 Apr 2025

    The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.

    Published: 21 Oct 2015
    8.8
    High

    CVE-2015-7849

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets.

    Published: 21 Oct 2015
    6.5
    Medium

    CVE-2015-7850

    Last Modified: 20 Apr 2025

    ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by pointing the key file at the log file.

    Published: 21 Oct 2015
    6.5
    Medium

    CVE-2015-7851

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated users to overwrite arbitrary files.

    Published: 21 Oct 2015
    5.9
    Medium

    CVE-2015-7852

    Last Modified: 20 Apr 2025

    ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets.

    Published: 21 Oct 2015
    2.3
    Low

    CVE-2015-7884

    Last Modified: 12 Apr 2025

    The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.

    Published: 21 Oct 2015
    2.3
    Low

    CVE-2015-7885

    Last Modified: 12 Apr 2025

    The dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mgmt.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.

    Published: 21 Oct 2015
    5.3
    Medium

    CVE-2015-4902

    Last Modified: 22 Apr 2026

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-4803

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60; Java SE Embedded 8u51; and JRockit R28.3.7 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2015-4893 and CVE-2015-4911.

    Published: 20 Oct 2015
    6.4
    Medium

    CVE-2015-4806

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-4842

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via vectors related to JAXP.

    Published: 20 Oct 2015
    10
    Critical

    CVE-2015-4881

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2015-4835.

    Published: 20 Oct 2015
    7.5
    High

    CVE-2011-5325

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-4734

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85 and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via vectors related to JGSS.

    Published: 20 Oct 2015
    10
    Critical

    CVE-2015-4805

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serialization.

    Published: 20 Oct 2015
    6.9
    Medium

    CVE-2015-4810

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u85 and 8u60 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

    Published: 20 Oct 2015
    10
    Critical

    CVE-2015-4835

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2015-4881.

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-4840

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u85 and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via unknown vectors related to 2D.

    Published: 20 Oct 2015
    10
    Critical

    CVE-2015-4843

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

    Published: 20 Oct 2015
    10
    Critical

    CVE-2015-4844

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

    Published: 20 Oct 2015
    10
    Critical

    CVE-2015-4860

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI, a different vulnerability than CVE-2015-4883.

    Published: 20 Oct 2015
    7.6
    High

    CVE-2015-4868

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8u60 and Java SE Embedded 8u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

    Published: 20 Oct 2015
    5.8
    Medium

    CVE-2015-4871

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u85 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-4872

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60; Java SE Embedded 8u51; and JRockit R28.3.7 allows remote attackers to affect integrity via unknown vectors related to Security.

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-4882

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect availability via vectors related to CORBA.

    Published: 20 Oct 2015
    10
    Critical

    CVE-2015-4883

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI, a different vulnerability than CVE-2015-4860.

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-4893

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60; Java SE Embedded 8u51; and JRockit R28.3.7 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2015-4803 and CVE-2015-4911.

    Published: 20 Oct 2015
    9.3
    Critical

    CVE-2015-4901

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8u60 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to JavaFX.

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-4903

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via vectors related to RMI.

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-4906

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors related to JavaFX, a different vulnerability than CVE-2015-4908 and CVE-2015-4916.

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-4908

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2015-4906 and CVE-2015-4916.

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-4911

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60; Java SE Embedded 8u51; and JRockit R28.3.7 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2015-4803 and CVE-2015-4893.

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-4916

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2015-4906 and CVE-2015-4908.

    Published: 20 Oct 2015
    6
    Medium

    CVE-2015-5242

    Last Modified: 12 Apr 2025

    OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs).

    Published: 20 Oct 2015
    5
    Medium

    CVE-2015-7750

    Last Modified: 12 Apr 2025

    The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2TP packet.

    Published: 19 Oct 2015
    10
    Critical

    CVE-2015-7860

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the agent in Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code by sending a large amount of data in an environment that lacks relationship-based firewalling.

    Published: 19 Oct 2015
    6.9
    Medium

    CVE-2015-7751

    Last Modified: 12 Apr 2025

    Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D35, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.1X50 before 14.1X50-D105, 14.1X51 before 14.1X51-D70, 14.1X53 before 14.1X53-D25, 14.1X55 before 14.1X55-D20, 14.2 before 14.2R1, 15.1 before 15.1F2 or 15.1R1, and 15.1X49 before 15.1X49-D10 does not require a password for the root user when pam.conf is "corrupted," which allows local users to gain root privileges by modifying the file.

    Published: 19 Oct 2015
    7.8
    High

    CVE-2015-7752

    Last Modified: 12 Apr 2025

    The SSH server in Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D10, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D35, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.1X53 before 14.1X53-D25, 14.2 before 14.2R3, 15.1 before 15.1R1, and 15.1X49 before 15.1X49-D20 allows remote attackers to cause a denial of service (CPU consumption) via unspecified SSH traffic.

    Published: 19 Oct 2015
    10
    Critical

    CVE-2015-7861

    Last Modified: 12 Apr 2025

    Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code by sending unspecified commands in an environment that lacks relationship-based firewalling.

    Published: 19 Oct 2015
    5
    Medium

    CVE-2015-7748

    Last Modified: 12 Apr 2025

    Juniper chassis with Trio (Trinity) chipset line cards and Junos OS 13.3 before 13.3R8, 14.1 before 14.1R6, 14.2 before 14.2R5, and 15.1 before 15.1R2 allow remote attackers to cause a denial of service (MPC line card crash) via a crafted uBFD packet.

    Published: 19 Oct 2015
    7.8
    High

    CVE-2015-7749

    Last Modified: 12 Apr 2025

    The PFE daemon in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service via an unspecified connection request to the "host-OS."

    Published: 19 Oct 2015
    5
    Medium

    CVE-2015-7862

    Last Modified: 12 Apr 2025

    Persistent Accelerite Radia Client Automation (formerly HP Client Automation) 7.9 through 9.1 before 2015-02-19 improperly implements the Role Based Access Control feature, which might allow remote attackers to modify an account's role assignments via unspecified vectors.

    Published: 19 Oct 2015
    5
    Medium

    CVE-2015-7863

    Last Modified: 12 Apr 2025

    The default configuration of Persistent Accelerite Radia Client Automation (formerly HP Client Automation) 7.9 through 9.1 before 2015-02-19 enables a remote Notify capability without the Extended Notify Security features, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 19 Oct 2015
    6.1
    Medium

    CVE-2015-6477

    Last Modified: 2 Jun 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Oct 2015
    4.3
    Medium

    CVE-2015-7032

    Last Modified: 12 Apr 2025

    The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted document.

    Published: 18 Oct 2015
    6.8
    Medium

    CVE-2015-7033

    Last Modified: 12 Apr 2025

    The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document.

    Published: 18 Oct 2015
    4.3
    Medium

    CVE-2015-5661

    Last Modified: 12 Apr 2025

    The SAND STUDIO AirDroid application 1.1.0 and earlier for Android mishandles implicit intents, which allows attackers to obtain sensitive information via a crafted application.

    Published: 18 Oct 2015