CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2015-3836

    Last Modified: 12 Apr 2025

    The Parse_wave function in arm-wt-22k/lib_src/eas_mdls.c in the Sonivox DLS-to-EAS converter in Android before 5.1.1 LMY48I does not reject a negative value for a certain size field, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted XMF data, aka internal bug 21132860.

    Published: 1 Oct 2015
    9.3
    Critical

    CVE-2015-3837

    Last Modified: 12 Apr 2025

    The OpenSSLX509Certificate class in org/conscrypt/OpenSSLX509Certificate.java in Android before 5.1.1 LMY48I improperly includes certain context data during serialization and deserialization, which allows attackers to execute arbitrary code via an application that sends a crafted Intent, aka internal bug 21437603.

    Published: 1 Oct 2015
    9.3
    Critical

    CVE-2015-3843

    Last Modified: 12 Apr 2025

    The SIM Toolkit (STK) framework in Android before 5.1.1 LMY48I allows attackers to (1) intercept or (2) emulate unspecified Telephony STK SIM commands via an application that sends a crafted Intent, related to com/android/internal/telephony/cat/AppInterface.java, aka internal bug 21697171.

    Published: 1 Oct 2015
    6.8
    Medium

    CVE-2015-3844

    Last Modified: 12 Apr 2025

    The getProcessRecordLocked method in services/core/java/com/android/server/am/ActivityManagerService.java in ActivityManager in Android before 5.1.1 LMY48I allows attackers to trigger incorrect process loading via a crafted application, as demonstrated by interfering with use of the Settings application, aka internal bug 21669445.

    Published: 1 Oct 2015
    6.8
    Medium

    CVE-2015-3845

    Last Modified: 12 Apr 2025

    The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of binder objects in an append operation, which allows attackers to obtain a different application's privileges via a crafted application, aka internal bug 17312693.

    Published: 1 Oct 2015
    9.3
    Critical

    CVE-2015-3849

    Last Modified: 12 Apr 2025

    The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android before 5.1.1 LMY48M does not check the return values of certain read operations, which allows attackers to execute arbitrary code via an application that sends a crafted message to a service, aka internal bug 21585255.

    Published: 1 Oct 2015
    5
    Medium

    CVE-2015-3861

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the addVorbisCodecInfo function in matroska/MatroskaExtractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allow remote attackers to cause a denial of service (device inoperability) via crafted Matroska data, aka internal bug 21296336.

    Published: 1 Oct 2015
    9.3
    Critical

    CVE-2015-3863

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary code and read arbitrary Keystore keys via an application that uses a crafted blob in an insert operation, aka internal bug 22802399.

    Published: 1 Oct 2015
    10
    Critical

    CVE-2015-3864

    Last Modified: 12 Apr 2025

    Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.

    Published: 1 Oct 2015
    7.5
    High

    CVE-2015-7384

    Last Modified: 20 Apr 2025

    Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.

    Published: 1 Oct 2015
    6.9
    Medium

    CVE-2015-7613

    Last Modified: 12 Apr 2025

    Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c.

    Published: 1 Oct 2015
    6.8
    Medium

    CVE-2015-7673

    Last Modified: 12 Apr 2025

    io-tga.c in gdk-pixbuf before 2.32.0 uses heap memory after its allocation failed, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) and possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file.

    Published: 1 Oct 2015
    6.8
    Medium

    CVE-2015-7803

    Last Modified: 12 Apr 2025

    The phar_get_entry_data function in ext/phar/util.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a .phar file with a crafted TAR archive entry in which the Link indicator references a file that does not exist.

    Published: 1 Oct 2015
    6.8
    Medium

    CVE-2015-7804

    Last Modified: 12 Apr 2025

    Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (uninitialized pointer dereference and application crash) by including the / filename in a .zip PHAR archive.

    Published: 1 Oct 2015
    5.9
    Medium

    CVE-2015-5293

    Last Modified: 20 Apr 2025

    Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.

    Published: 30 Sept 2015
    7.8
    High

    CVE-2015-7601

    Last Modified: 19 Aug 2026

    Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a RETR command.

    Published: 29 Sept 2015
    6.8
    Medium

    CVE-2015-5075

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators for requests that create an administrative account via a crafted request to index.php/users/create.

    Published: 29 Sept 2015
    7.8
    High

    CVE-2015-7603

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in a RETR command.

    Published: 29 Sept 2015
    4.3
    Medium

    CVE-2015-7604

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.2.x before 6.2.6 and Splunk Light 6.2.x before 6.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Sept 2015
    4
    Medium

    CVE-2015-0299

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Open Source Point of Sale 2.3.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Sept 2015
    7.5
    High

    CVE-2015-5074

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.9 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a .pht extension.

    Published: 29 Sept 2015
    4.3
    Medium

    CVE-2015-5076

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) version parameter in protected/views/admin/formEditor.php; the (2) importId parameter in protected/views/admin/rollbackImport.php; the (3) bc, (4) fg, (5) bgc, or (6) font parameter in protected/views/site/listener.php; the (7) Services[*] parameter in protected/components/views/webForm.php; the (8) file parameter in protected/components/TranslationManager.php; the (9) x2_key parameter in protected/tests/webscripts/x2WebTrackingTestPages/customWebLeadCaptureScriptTest.php; the (10) id parameter in protected/modules/contacts/controllers/ContactsController.php; or the (11) lastEventId parameter to index.php/profile/getEvents.

    Published: 29 Sept 2015
    7.5
    High

    CVE-2015-7319

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username.

    Published: 29 Sept 2015
    4.3
    Medium

    CVE-2015-7320

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Sept 2015
    6.8
    Medium

    CVE-2015-7337

    Last Modified: 12 Apr 2025

    The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.

    Published: 29 Sept 2015
    7.8
    High

    CVE-2015-7602

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in a RETR command.

    Published: 29 Sept 2015
    5
    Medium

    CVE-2015-0852

    Last Modified: 12 Apr 2025

    Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.

    Published: 29 Sept 2015
    4.6
    Medium

    CVE-2015-5442

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Software Update before 5.005.002.002 allows local users to gain privileges via unknown vectors.

    Published: 29 Sept 2015
    4
    Medium

    CVE-2015-5711

    Last Modified: 12 Apr 2025

    TIBCO Managed File Transfer Internet Server before 7.2.5, Managed File Transfer Command Center before 7.2.5, Slingshot before 1.9.4, and Vault before 2.0.1 allow remote authenticated users to obtain sensitive information via a crafted HTTP request.

    Published: 29 Sept 2015
    6.9
    Medium

    CVE-2015-5950

    Last Modified: 12 Apr 2025

    The NVIDIA display driver R352 before 353.82 and R340 before 341.81 on Windows; R304 before 304.128, R340 before 340.93, and R352 before 352.41 on Linux; and R352 before 352.46 on GRID vGPU and vSGA allows local users to write to an arbitrary kernel memory location and consequently gain privileges via a crafted ioctl call.

    Published: 29 Sept 2015
    4
    Medium

    CVE-2015-5435

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 3 before 1.85 and 4 before 2.22 allows remote authenticated users to cause a denial of service via unknown vectors.

    Published: 29 Sept 2015
    8.1
    High

    CVE-2015-7882

    Last Modified: 21 Nov 2024

    Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.

    Published: 29 Sept 2015
    6.5
    Medium

    CVE-2015-9274

    Last Modified: 21 Nov 2024

    HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh.

    Published: 29 Sept 2015
    10
    Critical

    CVE-2015-5957

    Last Modified: 12 Apr 2025

    Buffer overflow in the DumpSysVar function in var.c in Remind before 3.1.15 allows attackers to have unspecified impact via a long name.

    Published: 28 Sept 2015
    3.6
    Low

    CVE-2015-6927

    Last Modified: 12 Apr 2025

    vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs container (CT) root users to change the root password for arbitrary ploop containers, as demonstrated by a symlink attack on the ploop container root.hdd file and then access a control panel.

    Published: 28 Sept 2015
    5
    Medium

    CVE-2015-5372

    Last Modified: 12 Apr 2025

    The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 certificate embedded in the assertion against the certificate from the identity provider (IdP), which allows remote attackers to inject arbitrary SAML assertions via a crafted certificate.

    Published: 28 Sept 2015
    4.3
    Medium

    CVE-2015-5375

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in unspecified dialogs for printing content in the Front End in Open-Xchange Server 6 and OX App Suite before 6.22.8-rev8, 6.22.9 before 6.22.9-rev15m, 7.x before 7.6.1-rev25, and 7.6.2 before 7.6.2-rev20 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to object properties.

    Published: 28 Sept 2015
    7.5
    High

    CVE-2015-3203

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the href parameter.

    Published: 28 Sept 2015
    6.5
    Medium

    CVE-2015-5703

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the public key discovery API call in Open-Xchange OX Guard before 2.0.0-rev8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Sept 2015
    10
    Critical

    CVE-2015-5082

    Last Modified: 12 Apr 2025

    Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWORD_2 parameter to cgi-bin/chpasswd.cgi.

    Published: 28 Sept 2015
    6.8
    Medium

    CVE-2015-6928

    Last Modified: 12 Apr 2025

    classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the email parameter.

    Published: 28 Sept 2015
    3.5
    Low

    CVE-2015-7386

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in includes/metaboxes.php in the Gallery - Photo Albums - Portfolio plugin 1.3.47 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) Media Title or (2) Media Subtitle fields.

    Published: 28 Sept 2015
    7.5
    High

    CVE-2015-7387

    Last Modified: 12 Apr 2025

    ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query parameter to event/runQuery.do, as demonstrated by "SELECT 1;INSERT INTO." Fixed in Build 11200.

    Published: 28 Sept 2015
    4.3
    Medium

    CVE-2015-6010

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allow remote attackers to inject arbitrary web script or HTML via the (1) errorNo or (2) errorMsg parameter to error.php; the (3) viewType parameter to duplicate_manager.php; the (4) queryAction, (5) displayType, (6) citeOrder, (7) sqlQuery, (8) showQuery, (9) showLinks, (10) showRows, or (11) queryID parameter to query_manager.php; the (12) sourceText or (13) sourceIDs parameter to import.php; or the (14) typeName or (15) fileName parameter to modify.php.

    Published: 28 Sept 2015
    5.8
    Medium

    CVE-2015-6463

    Last Modified: 12 Apr 2025

    CodeWrights HART Comm DTM components, as used with Endress+Hauser FieldCare, allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a longtag XML schema containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 28 Sept 2015
    7.5
    High

    CVE-2015-7381

    Last Modified: 12 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary PHP code via the (1) pathToMYSQL or (2) databaseStructureFile parameter, a different issue than CVE-2015-6008.

    Published: 28 Sept 2015
    6.9
    Medium

    CVE-2014-9202

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in an unspecified DLL file in Advantech WebAccess before 8.0_20150816 allow remote attackers to execute arbitrary code via a crafted file that triggers long string arguments to functions.

    Published: 28 Sept 2015
    5
    Medium

    CVE-2015-6011

    Last Modified: 12 Apr 2025

    Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allows remote attackers to conduct XML injection attacks via (1) the id parameter to unapi.php or (2) the stylesheet parameter to sru.php.

    Published: 28 Sept 2015
    7.8
    High

    CVE-2015-6278

    Last Modified: 12 Apr 2025

    The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.2SE, 3.3SE, 3.3XO, 3.4SG, 3.5E, and 3.6E before 3.6.3E; 3.7E before 3.7.2E; 3.9S and 3.10S before 3.10.6S; 3.11S before 3.11.4S; 3.12S and 3.13S before 3.13.3S; and 3.14S before 3.14.2S does not properly implement the Control Plane Protection (aka CPPr) feature, which allows remote attackers to cause a denial of service (device reload) via a flood of ND packets, aka Bug ID CSCus19794.

    Published: 28 Sept 2015
    9.3
    Critical

    CVE-2015-6280

    Last Modified: 12 Apr 2025

    The SSHv2 functionality in Cisco IOS 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.6E before 3.6.3E, 3.7E before 3.7.1E, 3.10S before 3.10.6S, 3.11S before 3.11.4S, 3.12S before 3.12.3S, 3.13S before 3.13.3S, and 3.14S before 3.14.1S does not properly implement RSA authentication, which allows remote attackers to obtain login access by leveraging knowledge of a username and the associated public key, aka Bug ID CSCus73013.

    Published: 28 Sept 2015