CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2015-6482

    Last Modified: 12 Apr 2025

    Runtime Toolkit before 2.4.7.48 in 3S-Smart CODESYS before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted request.

    Published: 18 Oct 2015
    6.8
    Medium

    CVE-2015-7034

    Last Modified: 12 Apr 2025

    The Apple iWork application before 2.6 for iOS and Apple Pages before 5.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Pages document.

    Published: 18 Oct 2015
    5
    Medium

    CVE-2015-6843

    Last Modified: 12 Apr 2025

    Reviewer in EMC SourceOne Email Supervisor before 7.2 does not properly limit attempts to authenticate, which makes it easier for remote attackers to obtain access via a brute-force approach.

    Published: 18 Oct 2015
    4.3
    Medium

    CVE-2015-6844

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Reviewer in EMC SourceOne Email Supervisor before 7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Oct 2015
    7.5
    High

    CVE-2015-6845

    Last Modified: 12 Apr 2025

    EMC SourceOne Email Supervisor before 7.2 does not properly employ random values for session IDs, which makes it easier for remote attackers to obtain access by guessing an ID.

    Published: 18 Oct 2015
    6.8
    Medium

    CVE-2015-6846

    Last Modified: 12 Apr 2025

    EMC SourceOne Email Supervisor before 7.2 uses hardcoded encryption keys, which makes it easier for attackers to obtain access by examining how a program's code conducts cryptographic operations.

    Published: 18 Oct 2015
    4.3
    Medium

    CVE-2015-5444

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in HP Smart Profile Server Data Analytics Layer (SPS DAL) 2.3 before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Oct 2015
    6.4
    Medium

    CVE-2015-5662

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Avast before 150918-0 allows remote attackers to delete or write to arbitrary files via a crafted entry in a ZIP archive.

    Published: 18 Oct 2015
    7.5
    High

    CVE-2015-8012

    Last Modified: 21 Nov 2024

    lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malformed packet.

    Published: 18 Oct 2015
    9.8
    Critical

    CVE-2015-8863

    Last Modified: 12 Apr 2025

    Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.

    Published: 18 Oct 2015
    7.8
    High

    CVE-2015-8961

    Last Modified: 12 Apr 2025

    The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the Linux kernel before 4.3.3 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging improper access to a certain error field.

    Published: 18 Oct 2015
    2.1
    Low

    CVE-2015-5742

    Last Modified: 12 Apr 2025

    VeeamVixProxy in Veeam Backup & Replication (B&R) before 8.0 update 3 stores local administrator credentials in log files with world-readable permissions, which allows local users to obtain sensitive information by reading the files.

    Published: 16 Oct 2015
    7.8
    High

    CVE-2014-6450

    Last Modified: 12 Apr 2025

    Juniper Junos OS before 11.4R12-S4, 12.1X44 before 12.1X44-D41, 12.1X46 before 12.1X46-D26, 12.1X47 before 12.1X47-D11/D15, 12.2 before 12.2R9, 12.2X50 before 12.2X50-D70, 12.3 before 12.3R8, 12.3X48 before 12.3X48-D10, 12.3X50 before 12.3X50-D42, 13.1 before 13.1R4-S3, 13.1X49 before 13.1X49-D42, 13.1X50 before 13.1X50-D30, 13.2 before 13.2R6, 13.2X51 before 13.2X51-D26, 13.2X52 before 13.2X52-D15, 13.3 before 13.3R3-S3, 14.1 before 14.1R3, 14.2 before 14.2R1, 15.1 before 15.1R1, and 15.1X49 before 15.1X49-D10, when configured for IPv6, allow remote attackers to cause a denial of service (mbuf chain corruption and kernel panic) via crafted IPv6 packets.

    Published: 16 Oct 2015
    7.8
    High

    CVE-2014-6451

    Last Modified: 12 Apr 2025

    J-Web in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service (system reboot) via unspecified vectors.

    Published: 16 Oct 2015
    5
    Medium

    CVE-2014-6449

    Last Modified: 12 Apr 2025

    Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R8, 13.3 before 13.3R7, 14.1 before 14.1R5, and 14.2 before 14.2R1 do not properly handle TCP packet reassembly, which allows remote attackers to cause a denial of service (buffer consumption) via a crafted sequence of packets "destined to the device."

    Published: 16 Oct 2015
    4.3
    Medium

    CVE-2015-7377

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.

    Published: 16 Oct 2015
    6.5
    Medium

    CVE-2015-7682

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php.

    Published: 16 Oct 2015
    4
    Medium

    CVE-2015-7683

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in Font.php in the Font plugin before 7.5.1 for WordPress allows remote administrators to read arbitrary files via a full pathname in the url parameter to AjaxProxy.php.

    Published: 16 Oct 2015
    10
    Critical

    CVE-2015-7856

    Last Modified: 12 Apr 2025

    OpenNMS has a default password of rtc for the rtc account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.

    Published: 16 Oct 2015
    6.9
    Medium

    CVE-2015-4948

    Last Modified: 12 Apr 2025

    netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

    Published: 16 Oct 2015
    9.3
    Critical

    CVE-2015-6003

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

    Published: 16 Oct 2015
    4.6
    Medium

    CVE-2015-6333

    Last Modified: 12 Apr 2025

    Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

    Published: 16 Oct 2015
    6.8
    Medium

    CVE-2015-5660

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

    Published: 16 Oct 2015
    5
    Medium

    CVE-2015-6334

    Last Modified: 12 Apr 2025

    Cisco ASR 5000 and 5500 devices with software 18.0.0.57828 and 19.0.M0.61045 allow remote attackers to cause a denial of service (vpnmgr process restart) via a crafted header in a TACACS packet, aka Bug ID CSCuw01984.

    Published: 16 Oct 2015
    7.5
    High

    CVE-2016-0634

    Last Modified: 20 Apr 2025

    The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.

    Published: 16 Oct 2015
    5.8
    Medium

    CVE-2015-7990

    Last Modified: 12 Apr 2025

    Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6937.

    Published: 16 Oct 2015
    4
    Medium

    CVE-2015-8374

    Last Modified: 12 Apr 2025

    fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.

    Published: 16 Oct 2015
    6.5
    Medium

    CVE-2015-7725

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.091.00.1418659308 allow remote authenticated users to execute arbitrary SQL commands via the (1) remoteSourceName in the dropCredentials function or unspecified vectors in the (2) setTraceLevelsForXsApps, (3) _modifyUser, or (4) _newUser function, aka SAP Security Notes 2153898 and 2153765.

    Published: 15 Oct 2015
    3.5
    Low

    CVE-2015-7726

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in role deletion in the Web-based Development Workbench in SAP HANA DB 1.00.091.00.1418659308 allows remote authenticated users to inject arbitrary web script or HTML via the role name, aka SAP Security Note 2153898.

    Published: 15 Oct 2015
    7.2
    High

    CVE-2015-6507

    Last Modified: 12 Apr 2025

    The hdbsql client 1.00.091.00 Build 1418659308-1530 in SAP HANA allows local users to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors, aka SAP Security Note 2140700.

    Published: 15 Oct 2015
    9.3
    Critical

    CVE-2015-7361

    Last Modified: 12 Apr 2025

    FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the HA dedicated management interface, which allows remote attackers to obtain shell access via unspecified vectors.

    Published: 15 Oct 2015
    6.5
    Medium

    CVE-2015-7727

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors in the (1) trace configuration page or (2) getSqlTraceConfiguration function, aka SAP Security Note 2153898.

    Published: 15 Oct 2015
    3.5
    Low

    CVE-2015-7728

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in user creation in the Web-based Development Workbench in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to inject arbitrary web script or HTML via the username, aka SAP Security Note 2153898.

    Published: 15 Oct 2015
    6.5
    Medium

    CVE-2015-7729

    Last Modified: 12 Apr 2025

    Eval injection in test-net.xsjs in the Web-based Development Workbench in SAP HANA Developer Edition DB 1.00.091.00.1418659308 allows remote authenticated users to execute arbitrary XSJS code via unspecified vectors, aka SAP Security Note 2153892.

    Published: 15 Oct 2015
    10
    Critical

    CVE-2015-7730

    Last Modified: 12 Apr 2025

    SAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of service (out-of-bounds read and listener crash) via a crafted GIOP packet, aka SAP Security Note 2001108.

    Published: 15 Oct 2015
    10
    Critical

    CVE-2015-7838

    Last Modified: 12 Apr 2025

    ProcessFileUpload.jsp in SolarWinds Storage Manager before 6.2 allows remote attackers to upload and execute arbitrary files via unspecified vectors.

    Published: 15 Oct 2015
    7.5
    High

    CVE-2015-7839

    Last Modified: 12 Apr 2025

    SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebroker/nonsecurestreamingamf involving the traceroute functionality.

    Published: 15 Oct 2015
    7.5
    High

    CVE-2015-7840

    Last Modified: 12 Apr 2025

    The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code via unspecified vectors involving the ping feature.

    Published: 15 Oct 2015
    7.8
    High

    CVE-2013-7445

    Last Modified: 12 Apr 2025

    The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated by JavaScript code that creates many CANVAS elements for rendering by Chrome or Firefox.

    Published: 15 Oct 2015
    4.3
    Medium

    CVE-2015-5178

    Last Modified: 12 Apr 2025

    The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.

    Published: 15 Oct 2015
    6.8
    Medium

    CVE-2015-5188

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.CR9 allows remote attackers to hijack the authentication of administrators for requests that make arbitrary changes to an instance via vectors involving a file upload using a multipart/form-data submission.

    Published: 15 Oct 2015
    5
    Medium

    CVE-2015-5220

    Last Modified: 12 Apr 2025

    The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.

    Published: 15 Oct 2015
    5
    Medium

    CVE-2015-5302

    Last Modified: 12 Apr 2025

    libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1) backtrace, (2) cmdline, (3) environ, (4) open_fds, (5) maps, (6) smaps, (7) hostname, (8) remote, (9) ks.cfg, or (10) anaconda-tb file attachment included in a Red Hat Bugzilla bug report.

    Published: 15 Oct 2015
    6.8
    Medium

    CVE-2015-5306

    Last Modified: 12 Apr 2025

    OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error.

    Published: 15 Oct 2015
    6.8
    Medium

    CVE-2015-7184

    Last Modified: 12 Apr 2025

    The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is improperly followed, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

    Published: 15 Oct 2015
    9.8
    Critical

    CVE-2015-8011

    Last Modified: 21 Nov 2024

    Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.

    Published: 15 Oct 2015
    10
    Critical

    CVE-2015-5586

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6683, CVE-2015-6684, CVE-2015-6687, CVE-2015-6688, CVE-2015-6689, CVE-2015-6690, CVE-2015-6691, CVE-2015-7615, CVE-2015-7617, and CVE-2015-7621.

    Published: 14 Oct 2015
    10
    Critical

    CVE-2015-6687

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5586, CVE-2015-6683, CVE-2015-6684, CVE-2015-6688, CVE-2015-6689, CVE-2015-6690, CVE-2015-6691, CVE-2015-7615, CVE-2015-7617, and CVE-2015-7621.

    Published: 14 Oct 2015
    6.8
    Medium

    CVE-2015-6693

    Last Modified: 12 Apr 2025

    The signatureSetSeedValue method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted arguments, a different vulnerability than CVE-2015-6685, CVE-2015-6686, CVE-2015-6694, CVE-2015-6695, and CVE-2015-7622.

    Published: 14 Oct 2015
    4.3
    Medium

    CVE-2015-6699

    Last Modified: 12 Apr 2025

    The addForegroundSprite function in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to obtain sensitive information from process memory via invalid arguments, a different vulnerability than CVE-2015-6697, CVE-2015-6700, CVE-2015-6701, CVE-2015-6702, CVE-2015-6703, and CVE-2015-6704.

    Published: 14 Oct 2015