CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2015-5915

    Last Modified: 12 Apr 2025

    Apple OS X before 10.11 does not ensure that the keychain's lock state is displayed correctly, which has unspecified impact and attack vectors.

    Published: 9 Oct 2015
    5
    Medium

    CVE-2015-5917

    Last Modified: 12 Apr 2025

    The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring.

    Published: 9 Oct 2015
    10
    Critical

    CVE-2015-5922

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has unknown impact and attack vectors.

    Published: 9 Oct 2015
    2.1
    Low

    CVE-2015-5923

    Last Modified: 12 Apr 2025

    Apple iOS before 9.0.2 does not properly restrict the options available on the lock screen, which allows physically proximate attackers to read contact data or view photos via unspecified vectors.

    Published: 9 Oct 2015
    5
    Medium

    CVE-2015-7760

    Last Modified: 12 Apr 2025

    libxpc in launchd in Apple OS X before 10.11 does not restrict the creation of processes for network connections, which allows remote attackers to cause a denial of service (resource consumption) by repeatedly connecting to the SSH port, a different vulnerability than CVE-2015-7761.

    Published: 9 Oct 2015
    5
    Medium

    CVE-2015-7761

    Last Modified: 12 Apr 2025

    Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers to obtain sensitive information via an unspecified action during the printing of an e-mail message, a different vulnerability than CVE-2015-7760.

    Published: 9 Oct 2015
    4.3
    Medium

    CVE-2015-5654

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Dojo Toolkit before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Oct 2015
    7
    High

    CVE-2015-5649

    Last Modified: 12 Apr 2025

    Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended login restrictions or obtain sensitive information, by leveraging certain group-administration privileges.

    Published: 8 Oct 2015
    6.1
    Medium

    CVE-2015-6311

    Last Modified: 12 Apr 2025

    Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0), 7.3(101.0), and 7.4(1.19) allow remote attackers to cause a denial of service (device outage) by sending malformed 802.11i management data to a managed access point, aka Bug ID CSCub65236.

    Published: 8 Oct 2015
    5
    Medium

    CVE-2015-6310

    Last Modified: 12 Apr 2025

    The REST interface in Cisco Unified Communications Manager IM and Presence Service 11.5(1) allows remote attackers to cause a denial of service (SIP proxy service restart) via a crafted HTTP request, aka Bug ID CSCuw31632.

    Published: 8 Oct 2015
    Unknown

    CVE-2015-5128

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 8 Oct 2015
    9.8
    Critical

    CVE-2015-5284

    Last Modified: 20 Apr 2025

    ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.

    Published: 8 Oct 2015
    6.4
    Medium

    CVE-2015-5288

    Last Modified: 12 Apr 2025

    The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt.

    Published: 8 Oct 2015
    6.4
    Medium

    CVE-2015-5289

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.

    Published: 8 Oct 2015
    4.9
    Medium

    CVE-2015-7799

    Last Modified: 12 Apr 2025

    The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXCID ioctl call.

    Published: 8 Oct 2015
    4.9
    Medium

    CVE-2015-7833

    Last Modified: 12 Apr 2025

    The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor.

    Published: 8 Oct 2015
    6.4
    Medium

    CVE-2015-8241

    Last Modified: 12 Apr 2025

    The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.

    Published: 8 Oct 2015
    5
    Medium

    CVE-2015-3862

    Last Modified: 12 Apr 2025

    mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22954006.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-3870

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22771132.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-3871

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23031033.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-3872

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23346388.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-3873

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 23016072, 23248776, 23247055, 22845824, 22008959, 21814993, 21048776, 20718524, 20674674, 22388975, 20674086, 21443020, and 22077698, a different vulnerability than CVE-2015-7716.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-6599

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23416608.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-6600

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22882938.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-6601

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 22935234.

    Published: 6 Oct 2015
    5
    Medium

    CVE-2015-6605

    Last Modified: 12 Apr 2025

    mediaserver in Android before 5.1.1 LMY48T allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bugs 20915134 and 23142203, a different vulnerability than CVE-2015-7718.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-6603

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23227354.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-6604

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23129786.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-3823

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 21335999.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-3874

    Last Modified: 12 Apr 2025

    The Sonivox components in Android before 5.1.1 LMY48T allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 23335715, 23307276, and 23286323.

    Published: 6 Oct 2015
    4.3
    Medium

    CVE-2015-3878

    Last Modified: 12 Apr 2025

    Media Projection in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to bypass an intended screen-recording warning feature and obtain sensitive screen-snapshot information via a crafted application that references a long application name, aka internal bug 23345192.

    Published: 6 Oct 2015
    9.3
    Critical

    CVE-2015-6606

    Last Modified: 12 Apr 2025

    The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 22301786.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-3869

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23036083.

    Published: 6 Oct 2015
    6.4
    Medium

    CVE-2015-3847

    Last Modified: 12 Apr 2025

    Bluetooth in Android before 5.1.1 LMY48T allows attackers to remove stored SMS messages via a crafted application, aka internal bug 22343270.

    Published: 6 Oct 2015
    9.3
    Critical

    CVE-2015-3865

    Last Modified: 12 Apr 2025

    The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23050463.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-3867

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23213430.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-3868

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23270724.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-3875

    Last Modified: 12 Apr 2025

    libutils in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, aka internal bug 22952485.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-3877

    Last Modified: 12 Apr 2025

    Skia, as used in Android before 5.1.1 LMY48T, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20723696.

    Published: 6 Oct 2015
    9.3
    Critical

    CVE-2015-3879

    Last Modified: 12 Apr 2025

    Media Player Framework in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bug 23223325.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-6598

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23306638.

    Published: 6 Oct 2015
    9.3
    Critical

    CVE-2015-6596

    Last Modified: 12 Apr 2025

    mediaserver in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bugs 20731946 and 20719651, a different vulnerability than CVE-2015-7717.

    Published: 6 Oct 2015
    6.8
    Medium

    CVE-2015-6607

    Last Modified: 12 Apr 2025

    SQLite before 3.8.9, as used in Android before 5.1.1 LMY48T, allows attackers to gain privileges via a crafted application, aka internal bug 20099586.

    Published: 6 Oct 2015
    7.2
    High

    CVE-2015-7600

    Last Modified: 12 Apr 2025

    Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the ApplicationLauncher section.

    Published: 6 Oct 2015
    10
    Critical

    CVE-2015-7716

    Last Modified: 12 Apr 2025

    libstagefright in Android 5.x before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 20721050, a different vulnerability than CVE-2015-3873.

    Published: 6 Oct 2015
    9.3
    Critical

    CVE-2015-7717

    Last Modified: 12 Apr 2025

    mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.

    Published: 6 Oct 2015
    5
    Medium

    CVE-2015-7718

    Last Modified: 12 Apr 2025

    mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to cause a denial of service (process crash) via unspecified vectors, aka internal bug 22278703, a different vulnerability than CVE-2015-6605.

    Published: 6 Oct 2015
    7.5
    High

    CVE-2018-18066

    Last Modified: 6 May 2025

    snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.

    Published: 6 Oct 2015
    7.8
    High

    CVE-2015-8875

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops.c in gdk-pixbuf before 2.33.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image, which triggers a heap-based buffer overflow.

    Published: 6 Oct 2015
    5.4
    Medium

    CVE-2015-5181

    Last Modified: 20 Apr 2025

    The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.

    Published: 6 Oct 2015