CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2015-5182

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.

    Published: 6 Oct 2015
    7.5
    High

    CVE-2015-5183

    Last Modified: 20 Apr 2025

    Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.

    Published: 6 Oct 2015
    7.5
    High

    CVE-2015-5184

    Last Modified: 20 Apr 2025

    Console: CORS headers set to allow all in Red Hat AMQ.

    Published: 6 Oct 2015
    7.1
    High

    CVE-2015-5261

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.

    Published: 6 Oct 2015
    5
    Medium

    CVE-2015-7322

    Last Modified: 12 Apr 2025

    The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 provides different messages for attempts to join a meeting depending on the status of the meeting, which allows remote attackers to enumerate valid meeting ids via a series of requests.

    Published: 5 Oct 2015
    3.5
    Low

    CVE-2015-7323

    Last Modified: 12 Apr 2025

    The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 allows remote authenticated users to bypass intended access restrictions and log into arbitrary meetings by leveraging a meeting id and meetingAppSun.jar.

    Published: 5 Oct 2015
    6.5
    Medium

    CVE-2015-7707

    Last Modified: 12 Apr 2025

    Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.

    Published: 5 Oct 2015
    4.3
    Medium

    CVE-2015-7708

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat_description parameter in an updatecat action to admin/categories.php.

    Published: 5 Oct 2015
    10
    Critical

    CVE-2015-7709

    Last Modified: 12 Apr 2025

    The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.

    Published: 5 Oct 2015
    7.5
    High

    CVE-2015-7392

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allows remote attackers to execute arbitrary code via a trailing \u in a json string to cJSON_Parse.

    Published: 5 Oct 2015
    7.5
    High

    CVE-2015-5687

    Last Modified: 12 Apr 2025

    system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.

    Published: 5 Oct 2015
    4
    Medium

    CVE-2015-7685

    Last Modified: 12 Apr 2025

    GLPI before 0.85.3 allows remote authenticated users to create super-admin accounts by leveraging permissions to create a user and the _profiles_id parameter to front/user.form.php.

    Published: 5 Oct 2015
    9
    Critical

    CVE-2015-7684

    Last Modified: 12 Apr 2025

    Unrestricted file upload in GLPI before 0.85.3 allows remote authenticated users to execute arbitrary code by adding a file with an executable extension as an attachment to a new ticket, then accessing it via a direct request to the file in files/_tmp/.

    Published: 5 Oct 2015
    4.3
    Medium

    CVE-2015-4973

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 5 Oct 2015
    4.3
    Medium

    CVE-2015-4939

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Emptoris Supplier Lifecycle Management and Emptoris Program Management 10.x before 10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x before 10.0.3.2, and 10.0.4.x before 10.0.4.0_iFix1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 5 Oct 2015
    3.5
    Low

    CVE-2015-4944

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX003, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX003 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 5 Oct 2015
    6
    Medium

    CVE-2015-4964

    Last Modified: 12 Apr 2025

    IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allows remote authenticated users to gain privileges by leveraging the ability to create and execute a process.

    Published: 5 Oct 2015
    4
    Medium

    CVE-2015-4965

    Last Modified: 12 Apr 2025

    maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to obtain sensitive information by reading a (1) backup or (2) debug application file.

    Published: 5 Oct 2015
    6.5
    Medium

    CVE-2015-4967

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 and 7.6.0 before 7.6.0.1 IFIX002 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 5 Oct 2015
    3.5
    Low

    CVE-2015-4971

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Emptoris Strategic Supply Management Platform and Emptoris Program Management 10.x before 10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x before 10.0.3.2, and 10.0.4.x before 10.0.4.0_iFix1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 5 Oct 2015
    3.5
    Low

    CVE-2015-4992

    Last Modified: 12 Apr 2025

    IBM Sterling B2B Integrator 5.2 before 5020500_8 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.

    Published: 5 Oct 2015
    4
    Medium

    CVE-2015-5024

    Last Modified: 12 Apr 2025

    IBM Emptoris Sourcing 10.0.2.0 before iFix6, 10.0.2.2 before iFix11, 10.0.2.3, 10.0.2.5 before iFix4, 10.0.2.6 before iFix8, 10.0.2.7 before iFix1, and 10.0.4.x before iFix2 allows remote authenticated users to obtain sensitive supplier-bid information via unspecified vectors.

    Published: 5 Oct 2015
    4.3
    Medium

    CVE-2015-5022

    Last Modified: 12 Apr 2025

    IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2, when access by guests is enabled, place an internal hostname and a payload path in a response, which allows remote authenticated users to obtain sensitive information by leveraging a trading-partner relationship and reading response fields.

    Published: 5 Oct 2015
    7.2
    High

    CVE-2015-5652

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in python.exe in Python through 3.5.0 on Windows allows local users to gain privileges via a Trojan horse readline.pyd file in the current working directory. NOTE: the vendor says "It was determined that this is a longtime behavior of Python that cannot really be altered at this point."

    Published: 5 Oct 2015
    9.8
    Critical

    CVE-2015-7545

    Last Modified: 12 Apr 2025

    The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.

    Published: 5 Oct 2015
    5
    Medium

    CVE-2015-7713

    Last Modified: 12 Apr 2025

    OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.

    Published: 5 Oct 2015
    4.3
    Medium

    CVE-2015-2025

    Last Modified: 12 Apr 2025

    IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

    Published: 4 Oct 2015
    2.1
    Low

    CVE-2015-1933

    Last Modified: 12 Apr 2025

    IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX001 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not have an off autocomplete attribute for the password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

    Published: 4 Oct 2015
    5
    Medium

    CVE-2015-1934

    Last Modified: 12 Apr 2025

    IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX002 and 7.6.0 before 7.6.0.1 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly encrypt passwords, which makes it easier for context-dependent attackers to determine cleartext passwords by leveraging access to a password file.

    Published: 4 Oct 2015
    3.5
    Low

    CVE-2015-1983

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Projects page in IBM UrbanCode Build 6.1.x before 6.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 4 Oct 2015
    9
    Critical

    CVE-2015-2011

    Last Modified: 12 Apr 2025

    The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.

    Published: 4 Oct 2015
    6
    Medium

    CVE-2015-2026

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 4 Oct 2015
    9
    Critical

    CVE-2015-4930

    Last Modified: 12 Apr 2025

    IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges by leveraging admin access.

    Published: 4 Oct 2015
    3.5
    Low

    CVE-2015-1969

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Tivoli Common Reporting (TCR) 2.1 before IF13 and 2.1.1 before IF21, and TCR 3.1.x as used in Cognos Business Intelligence before 10.2 IF0015 and other products, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 4 Oct 2015
    3.5
    Low

    CVE-2015-1988

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Tivoli Storage Manger for Virtual Environments: Data Protection for VMware 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.3 and Tivoli Storage FlashCopy Manager for VMware 3.1 before 3.1.1.3, 3.2 before 3.2.0.6, and 4.1 before 4.1.3.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 4 Oct 2015
    9
    Critical

    CVE-2015-2016

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unknown vectors.

    Published: 4 Oct 2015
    2.1
    Low

    CVE-2015-2027

    Last Modified: 12 Apr 2025

    IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 improperly performs logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.

    Published: 4 Oct 2015
    4.3
    Medium

    CVE-2015-2028

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

    Published: 4 Oct 2015
    4.3
    Medium

    CVE-2015-2029

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to hijack web sessions via a session identifier.

    Published: 4 Oct 2015
    5
    Medium

    CVE-2015-2030

    Last Modified: 12 Apr 2025

    IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 4 Oct 2015
    3.5
    Low

    CVE-2015-2031

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 4 Oct 2015
    8.8
    High

    CVE-2015-7747

    Last Modified: 13 Aug 2025

    Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by sixteen-stereo-to-eight-mono.c.

    Published: 4 Oct 2015
    4
    Medium

    CVE-2015-0142

    Last Modified: 12 Apr 2025

    IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to cause a denial of service (maintenance-mode transition and data-storage outage) by calling the System Administration Mode function.

    Published: 3 Oct 2015
    3.5
    Low

    CVE-2015-4955

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 before 8.5.6.0 CF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 3 Oct 2015
    4
    Medium

    CVE-2015-0143

    Last Modified: 12 Apr 2025

    IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to obtain sensitive information by reading error messages.

    Published: 3 Oct 2015
    3.5
    Low

    CVE-2015-0144

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-8916.

    Published: 3 Oct 2015
    3.5
    Low

    CVE-2014-8916

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0144.

    Published: 3 Oct 2015
    4
    Medium

    CVE-2015-0141

    Last Modified: 12 Apr 2025

    IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to modify arbitrary user filters via a JSON request.

    Published: 3 Oct 2015
    6.8
    Medium

    CVE-2015-0145

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 3 Oct 2015
    4.3
    Medium

    CVE-2015-0195

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Content Template Catalog 4.x before 4.1.4 for WebSphere Portal 8.0.x and 4.x before 4.3.1 for WebSphere Portal 8.5.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 3 Oct 2015