CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-7382

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary SQL commands via the defaultCharacterSet parameter, a different issue than CVE-2015-6009.

    Published: 28 Sept 2015
    4.3
    Medium

    CVE-2015-7383

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge through 2015-04-28 allow remote attackers to inject arbitrary web script or HTML via the (1) adminUserName, (2) pathToMYSQL, (3) databaseStructureFile, or (4) pathToBibutils parameter to install.php or the (5) adminUserName parameter to update.php.

    Published: 28 Sept 2015
    9
    Critical

    CVE-2015-3974

    Last Modified: 12 Apr 2025

    EasyIO EasyIO-30P-SF controllers with firmware before 0.5.21 and 2.x before 2.0.5.21, as used in Accutrol, Bar-Tech Automation, Infocon/EasyIO, Honeywell Automation India, Johnson Controls, SyxthSENSE, Transformative Wave Technologies, Tridium Asia Pacific, and Tridium Europe products, have a hardcoded password, which makes it easier for remote attackers to obtain access via unspecified vectors.

    Published: 28 Sept 2015
    6.8
    Medium

    CVE-2015-6007

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 28 Sept 2015
    7.5
    High

    CVE-2015-6008

    Last Modified: 12 Apr 2025

    install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword parameter, a different issue than CVE-2015-7381.

    Published: 28 Sept 2015
    7.5
    High

    CVE-2015-6009

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to rss.php or (2) the sqlQuery parameter to search.php, a different issue than CVE-2015-7382.

    Published: 28 Sept 2015
    5.8
    Medium

    CVE-2015-6012

    Last Modified: 12 Apr 2025

    Multiple open redirect vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the referrer parameter.

    Published: 28 Sept 2015
    7.8
    High

    CVE-2015-6279

    Last Modified: 12 Apr 2025

    The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.2SE, 3.3SE, 3.3XO, 3.4SG, 3.5E, and 3.6E before 3.6.3E; 3.7E before 3.7.2E; 3.9S and 3.10S before 3.10.6S; 3.11S before 3.11.4S; 3.12S and 3.13S before 3.13.3S; and 3.14S before 3.14.2S allows remote attackers to cause a denial of service (device reload) via a malformed ND packet with the Cryptographically Generated Address (CGA) option, aka Bug ID CSCuo04400.

    Published: 28 Sept 2015
    6.1
    Medium

    CVE-2015-6307

    Last Modified: 12 Apr 2025

    Cisco FirePOWER (formerly Sourcefire) 7000 and 8000 devices with software 5.4.0.1 allow remote attackers to cause a denial of service (inspection-engine outage) via crafted packets, aka Bug ID CSCuu10871.

    Published: 28 Sept 2015
    9
    Critical

    CVE-2015-8557

    Last Modified: 12 Apr 2025

    The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.

    Published: 28 Sept 2015
    7.8
    High

    CVE-2015-7686

    Last Modified: 12 Apr 2025

    Algorithmic complexity vulnerability in Address.pm in the Email-Address module 1.908 and earlier for Perl allows remote attackers to cause a denial of service (CPU consumption) via a crafted string containing a list of e-mail addresses in conjunction with parenthesis characters that can be associated with nested comments. NOTE: the default configuration in 1.908 mitigates this vulnerability but misparses certain realistic comments.

    Published: 27 Sept 2015
    7.5
    High

    CVE-2015-7375

    Last Modified: 12 Apr 2025

    Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash) via a crafted Indusoft Project file.

    Published: 25 Sept 2015
    7.5
    High

    CVE-2015-7374

    Last Modified: 12 Apr 2025

    The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-2649.

    Published: 25 Sept 2015
    4
    Medium

    CVE-2015-4543

    Last Modified: 12 Apr 2025

    EMC RSA Archer GRC 5.x before 5.5.3 uses cleartext for stored passwords in unspecified circumstances, which allows remote authenticated users to obtain sensitive information by reading database fields.

    Published: 25 Sept 2015
    6.5
    Medium

    CVE-2015-4542

    Last Modified: 12 Apr 2025

    EMC RSA Archer GRC 5.x before 5.5.3 allows remote authenticated users to bypass intended access restrictions, and read or modify Discussion Forum Fields messages, via unspecified vectors.

    Published: 25 Sept 2015
    5
    Medium

    CVE-2015-6454

    Last Modified: 12 Apr 2025

    Everest PeakHMI before 8.7.0.2, when the video server is used, allows remote attackers to cause a denial of service (incorrect pointer dereference and daemon crash) via a crafted packet.

    Published: 25 Sept 2015
    4.3
    Medium

    CVE-2015-4539

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG) before 7.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Sept 2015
    3.5
    Low

    CVE-2015-4540

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Identity Management & Governance (IMG) before 6.8.1 P18 and 6.9.x before 6.9.1 P6 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Sept 2015
    3.5
    Low

    CVE-2015-4541

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer GRC 5.x before 5.5.3 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Sept 2015
    7.8
    High

    CVE-2015-6282

    Last Modified: 12 Apr 2025

    Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15.1S allows remote attackers to cause a denial of service (device reload) via IPv4 packets that require NAT and MPLS actions, aka Bug ID CSCut96933.

    Published: 25 Sept 2015
    5
    Medium

    CVE-2015-6302

    Last Modified: 12 Apr 2025

    The RADIUS functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.0(250.0) and 7.0(252.0) allows remote attackers to disconnect arbitrary sessions via crafted Disconnect-Request UDP packets, aka Bug ID CSCuw29419.

    Published: 25 Sept 2015
    7.2
    High

    CVE-2015-6305

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConnect Secure Mobility Client 2.0 through 4.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by dbghelp.dll, aka Bug ID CSCuv01279. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-4211.

    Published: 25 Sept 2015
    7.2
    High

    CVE-2015-6306

    Last Modified: 12 Apr 2025

    Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation file, aka Bug ID CSCuv11947.

    Published: 25 Sept 2015
    6.8
    Medium

    CVE-2015-6468

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Resource Data Management Data Manager before 2.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 25 Sept 2015
    5
    Medium

    CVE-2015-6469

    Last Modified: 12 Apr 2025

    The interpreter in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allows remote attackers to discover script source code via unspecified vectors.

    Published: 25 Sept 2015
    5.5
    Medium

    CVE-2015-6470

    Last Modified: 12 Apr 2025

    Resource Data Management Data Manager before 2.2 allows remote authenticated users to modify arbitrary passwords via unspecified vectors.

    Published: 25 Sept 2015
    5
    Medium

    CVE-2015-6474

    Last Modified: 12 Apr 2025

    IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to discover cleartext passwords by reading HTML source code.

    Published: 25 Sept 2015
    4.3
    Medium

    CVE-2015-6475

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Sept 2015
    4
    Medium

    CVE-2015-2697

    Last Modified: 12 Apr 2025

    The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.

    Published: 25 Sept 2015
    4.3
    Medium

    CVE-2015-6303

    Last Modified: 12 Apr 2025

    The Cisco Spark application 2015-07-04 for mobile operating systems does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, aka Bug IDs CSCut36742 and CSCut36844.

    Published: 24 Sept 2015
    6.8
    Medium

    CVE-2015-6304

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Server software 3.0(2.24) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCut63718, CSCut63724, and CSCut63760.

    Published: 24 Sept 2015
    7.5
    High

    CVE-2015-1303

    Last Modified: 12 Apr 2025

    bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information about a cross-context exception, which allows remote attackers to bypass the Same Origin Policy via a crafted HTML document containing an IFRAME element.

    Published: 24 Sept 2015
    7.5
    High

    CVE-2015-1304

    Last Modified: 12 Apr 2025

    object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call.

    Published: 24 Sept 2015
    6.8
    Medium

    CVE-2015-5292

    Last Modified: 12 Apr 2025

    Memory leak in the Privilege Attribute Certificate (PAC) responder plugin (sssd_pac_plugin.so) in System Security Services Daemon (SSSD) 1.10 before 1.13.1 allows remote authenticated users to cause a denial of service (memory consumption) via a large number of logins that trigger parsing of PAC blobs during Kerberos authentication.

    Published: 23 Sept 2015
    5.5
    Medium

    CVE-2015-7802

    Last Modified: 12 Apr 2025

    gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.

    Published: 23 Sept 2015
    7.5
    High

    CVE-2016-7031

    Last Modified: 12 Apr 2025

    The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.

    Published: 23 Sept 2015
    5
    Medium

    CVE-2015-6940

    Last Modified: 12 Apr 2025

    The GetResource servlet in Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x, and 5.0.x through 5.2.x and Pentaho Data Integration (PDI) Suite 4.3.x, 4.4.x, and 5.0.x through 5.2.x does not restrict access to files in the pentaho-solutions/system folder, which allows remote attackers to obtain passwords and other sensitive information via a file name in the resource parameter.

    Published: 22 Sept 2015
    6.5
    Medium

    CVE-2015-7310

    Last Modified: 12 Apr 2025

    McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly handled when downloading the file.

    Published: 22 Sept 2015
    6.5
    Medium

    CVE-2015-7309

    Last Modified: 12 Apr 2025

    The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

    Published: 22 Sept 2015
    6.6
    Medium

    CVE-2015-4505

    Last Modified: 12 Apr 2025

    updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a junction attack and waiting for an update operation by the Mozilla Maintenance Service.

    Published: 22 Sept 2015
    6.4
    Medium

    CVE-2015-4512

    Last Modified: 12 Apr 2025

    gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) by using a CANVAS element to trigger 2D rendering.

    Published: 22 Sept 2015
    4.3
    Medium

    CVE-2015-4519

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect's target URL via crafted JavaScript code that executes after a drag-and-drop action of an image into a TEXTBOX element.

    Published: 22 Sept 2015
    4.9
    Medium

    CVE-2015-5257

    Last Modified: 12 Apr 2025

    drivers/usb/serial/whiteheat.c in the Linux kernel before 4.2.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted USB device. NOTE: this ID was incorrectly used for an Apache Cordova issue that has the correct ID of CVE-2015-8320.

    Published: 22 Sept 2015
    7.5
    High

    CVE-2015-7174

    Last Modified: 12 Apr 2025

    The nsAttrAndChildArray::GrowBy function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors, related to an "overflow."

    Published: 22 Sept 2015
    4.4
    Medium

    CVE-2015-7312

    Last Modified: 12 Apr 2025

    Multiple race conditions in the Advanced Union Filesystem (aufs) aufs3-mmap.patch and aufs4-mmap.patch patches for the Linux kernel 3.x and 4.x allow local users to cause a denial of service (use-after-free and BUG) or possibly gain privileges via a (1) madvise or (2) msync system call, related to mm/madvise.c and mm/msync.c.

    Published: 22 Sept 2015
    6.8
    Medium

    CVE-2015-4506

    Last Modified: 12 Apr 2025

    Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows remote attackers to execute arbitrary code via a crafted VP9 file.

    Published: 22 Sept 2015
    6.4
    Medium

    CVE-2015-4520

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation or (2) retrieval of a value from an incorrect HTTP Access-Control-* response header.

    Published: 22 Sept 2015
    8.1
    High

    CVE-2015-5232

    Last Modified: 20 Apr 2025

    Race conditions in opa-fm before 10.4.0.0.196 and opa-ff before 10.4.0.0.197.

    Published: 22 Sept 2015
    5.5
    Medium

    CVE-2015-5251

    Last Modified: 12 Apr 2025

    OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.

    Published: 22 Sept 2015
    7.5
    High

    CVE-2015-5271

    Last Modified: 12 Apr 2025

    The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.

    Published: 22 Sept 2015