CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-6460

    Last Modified: 12 Apr 2025

    Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.34 allow remote attackers to execute arbitrary code via opcode (1) 0x3ef or (2) 0x3f0.

    Published: 18 Sept 2015
    5.8
    Medium

    CVE-2015-6932

    Last Modified: 12 Apr 2025

    VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2015
    4.3
    Medium

    CVE-2015-6939

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the login module in Joomla! 3.4.x before 3.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Sept 2015
    7.5
    High

    CVE-2015-7243

    Last Modified: 12 Apr 2025

    Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted WAV file.

    Published: 18 Sept 2015
    5
    Medium

    CVE-2015-4638

    Last Modified: 12 Apr 2025

    The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.6.0 HF4, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.2.1 through 11.3.0, and BIG-IP PSM 11.2.1 through 11.4.1 allows remote attackers to cause a denial of service (Traffic Management Microkernel restart) via a fragmented packet.

    Published: 18 Sept 2015
    5
    Medium

    CVE-2015-7237

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the remote log viewing functionality in McAfee Agent (MA) 5.x before 5.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 18 Sept 2015
    7.5
    High

    CVE-2015-7239

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the BP_FIND_JOBS_WITH_PROGRAM function module in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 18 Sept 2015
    2.1
    Low

    CVE-2015-7238

    Last Modified: 12 Apr 2025

    The Secondary server in Threat Intelligence Exchange (TIE) before 1.2.0 uses weak permissions for unspecified (1) configuration files and (2) installation logs, which allows local users to obtain sensitive information by reading the files.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5789

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5796

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5803

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5810

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5817

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    4.3
    Medium

    CVE-2015-5825

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traffic via crafted JavaScript code.

    Published: 18 Sept 2015
    5
    Medium

    CVE-2015-5841

    Last Modified: 12 Apr 2025

    The CFNetwork Proxies component in Apple iOS before 9 does not properly handle a Set-Cookie header within a response to an HTTP CONNECT request, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.

    Published: 18 Sept 2015
    9.3
    Critical

    CVE-2015-5867

    Last Modified: 12 Apr 2025

    IOHIDFamily in Apple iOS before 9 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 18 Sept 2015
    3.3
    Low

    CVE-2015-5869

    Last Modified: 12 Apr 2025

    The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Apple iOS before 9 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.

    Published: 18 Sept 2015
    5
    Medium

    CVE-2015-5879

    Last Modified: 12 Apr 2025

    XNU in the kernel in Apple iOS before 9 does not properly validate the headers of TCP packets, which allows remote attackers to bypass the sequence-number protection mechanism and cause a denial of service (TCP connection disruption) via a crafted header.

    Published: 18 Sept 2015
    2.1
    Low

    CVE-2015-5892

    Last Modified: 12 Apr 2025

    Siri in Apple iOS before 9 allows physically proximate attackers to bypass an intended client-side protection mechanism and obtain sensitive content-notification information by listening to a device in the lock-screen state.

    Published: 18 Sept 2015
    10
    Critical

    CVE-2015-5911

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document.

    Published: 18 Sept 2015
    6.9
    Medium

    CVE-2014-8611

    Last Modified: 12 Apr 2025

    The __sflush function in fflush.c in stdio in libc in FreeBSD 10.1 and the kernel in Apple iOS before 9 mishandles failures of the write system call, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted application.

    Published: 18 Sept 2015
    5
    Medium

    CVE-2015-3801

    Last Modified: 12 Apr 2025

    The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intended single-cookie restriction via unspecified vectors.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5790

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5797

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5804

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5811

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    5
    Medium

    CVE-2015-5840

    Last Modified: 12 Apr 2025

    The checkint division routines in removefile in Apple iOS before 9 allow attackers to cause a denial of service (overflow fault and app crash) via crafted data.

    Published: 18 Sept 2015
    2.1
    Low

    CVE-2015-5842

    Last Modified: 12 Apr 2025

    XNU in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows local users to obtain sensitive memory-layout information via unknown vectors.

    Published: 18 Sept 2015
    2.1
    Low

    CVE-2015-5850

    Last Modified: 12 Apr 2025

    AppleKeyStore in Apple iOS before 9 allows physically proximate attackers to reset the count of incorrect passcode attempts via a device backup.

    Published: 18 Sept 2015
    2.1
    Low

    CVE-2015-5851

    Last Modified: 12 Apr 2025

    The convenience initializer in the Multipeer Connectivity component in Apple iOS before 9 does not require an encrypted session, which allows local users to obtain cleartext multipeer data via an encrypted-to-unencrypted downgrade attack.

    Published: 18 Sept 2015
    5
    Medium

    CVE-2015-5860

    Last Modified: 12 Apr 2025

    The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing protection mechanism and track users via a crafted web site.

    Published: 18 Sept 2015
    10
    Critical

    CVE-2015-5903

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5896.

    Published: 18 Sept 2015
    5
    Medium

    CVE-2015-5912

    Last Modified: 12 Apr 2025

    The CFNetwork FTPProtocol component in Apple iOS before 9 allows remote FTP proxy servers to trigger TCP connection attempts to intranet hosts via crafted responses.

    Published: 18 Sept 2015
    5
    Medium

    CVE-2015-5885

    Last Modified: 12 Apr 2025

    The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.

    Published: 18 Sept 2015
    7.2
    High

    CVE-2015-5848

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 18 Sept 2015
    4.3
    Medium

    CVE-2015-5764

    Last Modified: 12 Apr 2025

    The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5765 and CVE-2015-5767.

    Published: 18 Sept 2015
    4.3
    Medium

    CVE-2015-5765

    Last Modified: 12 Apr 2025

    The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5767.

    Published: 18 Sept 2015
    4.3
    Medium

    CVE-2015-5767

    Last Modified: 12 Apr 2025

    The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5765.

    Published: 18 Sept 2015
    4.3
    Medium

    CVE-2015-5835

    Last Modified: 12 Apr 2025

    Apple iOS before 9 allows attackers to obtain sensitive information about inter-app communication via a crafted app that conducts an interception attack involving an unspecified URL scheme.

    Published: 18 Sept 2015
    4.3
    Medium

    CVE-2015-5788

    Last Modified: 12 Apr 2025

    The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain sensitive image information via vectors involving a CANVAS element.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5791

    Last Modified: 12 Apr 2025

    WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5792

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5793

    Last Modified: 12 Apr 2025

    WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5794

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5795

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5798

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iTunes before 12.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5799

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5800

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5801

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015
    6.8
    Medium

    CVE-2015-5802

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

    Published: 18 Sept 2015