CVE Feed

    Dashboard / CVE

    2.6
    Low

    CVE-2015-5907

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9 allows man-in-the-middle attackers to conduct redirection attacks by leveraging the mishandling of the resource cache of an SSL web site with an invalid X.509 certificate.

    Published: 18 Sept 2015
    5
    Medium

    CVE-2015-5909

    Last Modified: 12 Apr 2025

    IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially sensitive build information in opportunistic circumstances by leveraging incorrect notification delivery.

    Published: 18 Sept 2015
    3.3
    Low

    CVE-2015-5910

    Last Modified: 12 Apr 2025

    IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 18 Sept 2015
    4.3
    Medium

    CVE-2015-5916

    Last Modified: 12 Apr 2025

    The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-transaction information during payments by leveraging the transaction-log feature.

    Published: 18 Sept 2015
    4.3
    Medium

    CVE-2015-5920

    Last Modified: 12 Apr 2025

    The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-middle attackers to discover encrypted SMB credentials via unspecified vectors.

    Published: 18 Sept 2015
    4.3
    Medium

    CVE-2015-5921

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9 mishandles "Content-Disposition: attachment" HTTP headers, which might allow man-in-the-middle attackers to obtain sensitive information via unspecified vectors.

    Published: 18 Sept 2015
    5
    Medium

    CVE-2015-7295

    Last Modified: 12 Apr 2025

    hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.

    Published: 18 Sept 2015
    2.1
    Low

    CVE-2015-1319

    Last Modified: 12 Apr 2025

    The Unity Settings Daemon before 14.04.0+14.04.20150825-0ubuntu2 and 15.04.x before 15.04.1+15.04.20150408-0ubuntu1.2 does not properly detect if the screen is locked, which allows physically proximate attackers to mount removable media while the screen is locked as demonstrated by inserting a USB thumb drive.

    Published: 17 Sept 2015
    3.5
    Low

    CVE-2015-7230

    Last Modified: 12 Apr 2025

    The Workbench Email module 7.x-3.x before 7.x-3.4 for Drupal allows remote authenticated users with certain permissions to bypass node and field validation by saving a node.

    Published: 17 Sept 2015
    4
    Medium

    CVE-2015-4040

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to access arbitrary files in the web root via unspecified vectors.

    Published: 17 Sept 2015
    10
    Critical

    CVE-2015-5538

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allow remote attackers to gain privileges via unknown vectors, related to the (1) Command Line Interface (CLI) and the (2) Web User Interface (UI).

    Published: 17 Sept 2015
    5
    Medium

    CVE-2015-7231

    Last Modified: 12 Apr 2025

    The Commerce Commonwealth (CBA) module 7.x-1.x before 7.x-1.5 for Drupal does not properly validate payments, which allows remote attackers to make a failed payment appear valid via a crafted URL, related to a "response from commweb."

    Published: 17 Sept 2015
    4.3
    Medium

    CVE-2015-6672

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Sept 2015
    3.5
    Low

    CVE-2015-7229

    Last Modified: 12 Apr 2025

    The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post to twitter" permission or change the options for arbitrary attached accounts by leveraging the (2) "add twitter accounts" or (3) "add authenticated twitter accounts" permission.

    Published: 17 Sept 2015
    5
    Medium

    CVE-2015-7226

    Last Modified: 12 Apr 2025

    The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the access handler.

    Published: 17 Sept 2015
    3.5
    Low

    CVE-2015-7227

    Last Modified: 12 Apr 2025

    The Fieldable Panels Panes module 7.x-1.x before 7.x-1.7 for Drupal does not properly check permissions to edit Fieldable Panels Panes entities, which allows remote authenticated users to edit panes by leveraging permissions to edit panels.

    Published: 17 Sept 2015
    5
    Medium

    CVE-2015-7228

    Last Modified: 12 Apr 2025

    The RESTful module 7.x-1.x before 7.x-1.3 for Drupal does not properly cache pages of authenticated users when using non-cookie authentication providers, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 17 Sept 2015
    2.6
    Low

    CVE-2015-7232

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in unspecified administration pages in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology module is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Sept 2015
    5.1
    Medium

    CVE-2015-7233

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Import module is enabled, allows remote attackers to hijack the authentication of administrators for requests that create new OSF datasets via unspecified vectors.

    Published: 17 Sept 2015
    4
    Medium

    CVE-2015-7234

    Last Modified: 12 Apr 2025

    The OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology and OSF Import modules are enabled, allows user-assisted remote attackers to delete arbitrary files via unspecified vectors.

    Published: 17 Sept 2015
    7.5
    High

    CVE-2015-7235

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a dex_reservations_calendar_load2 action or (2) dex_item parameter in a dex_reservations_check_posted_data action in a request to the default URI.

    Published: 17 Sept 2015
    7.5
    High

    CVE-2015-6962

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands via the email parameter to tkmonitor/estrutura/login/Login.actions.php.

    Published: 17 Sept 2015
    6.1
    Medium

    CVE-2015-5282

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.

    Published: 17 Sept 2015
    6.8
    Medium

    CVE-2015-6973

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via a crafted request to user-password.jsp, (2) add users via a crafted request to user-create.jsp, (3) edit server settings or (4) disable SSL on the server via a crafted request to server-props.jsp, or (5) add clients via a crafted request to plugins/clientcontrol/permitted-clients.jsp.

    Published: 16 Sept 2015
    4.3
    Medium

    CVE-2015-6972

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML via the (1) groupchatName parameter to plugins/clientcontrol/create-bookmark.jsp; the (2) urlName parameter to plugins/clientcontrol/create-bookmark.jsp; the (3) hostname parameter to server-session-details.jsp; or the (4) search parameter to group-summary.jsp.

    Published: 16 Sept 2015
    9
    Critical

    CVE-2014-8778

    Last Modified: 12 Apr 2025

    Checkmarx CxSAST (formerly CxSuite) before 7.1.8 allows remote authenticated users to bypass the CxQL sandbox protection mechanism and execute arbitrary C# code by asserting the (1) System.Security.Permissions.PermissionState.Unrestricted or (2) System.Security.Permissions.SecurityPermissionFlag.AllFlags permission.

    Published: 16 Sept 2015
    7.2
    High

    CVE-2015-5465

    Last Modified: 12 Apr 2025

    Silicon Integrated Systems WindowsXP Display Manager (aka VGA Driver Manager and VGA Display Manager) 6.14.10.3930 allows local users to gain privileges via a crafted (1) 0x96002400 or (2) 0x96002404 IOCTL call.

    Published: 16 Sept 2015
    4.3
    Medium

    CVE-2015-6929

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Nokia Networks (formerly Nokia Solutions and Networks and Nokia Siemens Networks) @vantage Commander allow remote attackers to inject arbitrary web script or HTML via the (1) idFilter or (2) nameFilter parameter to cftraces/filter/fl_copy.jsp; the (3) flName parameter to cftraces/filter/fl_crea1.jsp; the (4) serchStatus, (5) refreshTime, or (6) serchNode parameter to cftraces/process/pr_show_process.jsp; the (7) MaxActivationTime, (8) NumberOfBytes, (9) NumberOfTracefiles, (10) SessionName, or (11) serchSessionkind parameter to cftraces/session/se_crea.jsp; the (12) serchSessionDescription parameter to cftraces/session/se_show.jsp; the (13) serchApplication or (14) serchApplicationkind parameter to cftraces/session/tr_crea_filter.jsp; the (15) columKeyUnique, (16) columParameter, (17) componentName, (18) criteria1, (19) criteria2, (20) criteria3, (21) description, (22) filter, (23) id, (24) pathName, (25) tableName, or (26) component parameter to cftraces/session/tr_create_tagg_para.jsp; or the (27) userid parameter to home/certificate_association.jsp.

    Published: 16 Sept 2015
    7.5
    High

    CVE-2015-1173

    Last Modified: 12 Apr 2025

    Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode modules, which allows remote attackers to gain privileges via crafted "received parameters."

    Published: 16 Sept 2015
    6.4
    Medium

    CVE-2015-3623

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) attacks and read arbitrary files via crafted XML data in a request to AccessPoint.aspx.

    Published: 16 Sept 2015
    6.8
    Medium

    CVE-2015-6828

    Last Modified: 12 Apr 2025

    The tweet_info function in class/__functions.php in the SecureMoz Security Audit plugin 1.0.5 and earlier for WordPress does not use an HTTPS session for downloading serialized data, which allows man-in-the-middle attackers to conduct PHP object injection attacks and execute arbitrary PHP code by modifying the client-server data stream. NOTE: some of these details are obtained from third party information.

    Published: 16 Sept 2015
    6.8
    Medium

    CVE-2015-6966

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog before 4.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) create a post via a new_simple action to admin.php or (2) conduct cross-site scripting (XSS) attacks via the content parameter in a new_simple action to admin.php.

    Published: 16 Sept 2015
    4.9
    Medium

    CVE-2015-5440

    Last Modified: 12 Apr 2025

    HP UCMDB 10.00 and 10.01 before 10.01CUP12, 10.10 and 10.11 before 10.11CUP6, and 10.2x before 10.21 allows local users to obtain sensitive information via unspecified vectors.

    Published: 16 Sept 2015
    6.5
    Medium

    CVE-2015-6967

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.

    Published: 16 Sept 2015
    6.8
    Medium

    CVE-2015-6965

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) create a field, (2) update a field, (3) delete a field, (4) create a form, (5) update a form, (6) delete a form, (7) create a template, (8) update a template, (9) delete a template, or (10) conduct cross-site scripting (XSS) attacks via a crafted request to the cfg_forms page in wp-admin/admin.php.

    Published: 16 Sept 2015
    4
    Medium

    CVE-2015-2136

    Last Modified: 12 Apr 2025

    HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors.

    Published: 16 Sept 2015
    3.5
    Low

    CVE-2015-5956

    Last Modified: 12 Apr 2025

    The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as demonstrated by the (1) returnUrl parameter to show_rechis.php and the (2) redirect_url parameter to index.php.

    Published: 16 Sept 2015
    7.5
    High

    CVE-2015-6829

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the getip function in wp-limit-login-attempts.php in the WP Limit Login Attempts plugin before 2.0.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) X-Forwarded-For or (2) Client-IP HTTP header.

    Published: 16 Sept 2015
    6.5
    Medium

    CVE-2015-6968

    Last Modified: 12 Apr 2025

    Multiple incomplete blacklist vulnerabilities in the serendipity_isActiveFile function in include/functions_images.inc.php in Serendipity before 2.0.2 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .pht or (2) .phtml extension.

    Published: 16 Sept 2015
    4.3
    Medium

    CVE-2015-6969

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in js/2k11.min.js in the 2k11 theme in Serendipity before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via a user name in a comment, which is not properly handled in a Reply link.

    Published: 16 Sept 2015
    4.6
    Medium

    CVE-2015-5426

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP LoadRunner Controller before 12.50 allows local users to gain privileges via unknown vectors, aka ZDI-CAN-2756.

    Published: 16 Sept 2015
    6.5
    Medium

    CVE-2015-5274

    Last Modified: 12 Apr 2025

    rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.

    Published: 16 Sept 2015
    6.7
    Medium

    CVE-2015-5297

    Last Modified: 21 Nov 2024

    An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application using pixman to crash or, potentially, execute arbitrary code.

    Published: 16 Sept 2015
    Unknown

    CVE-2015-7118

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 16 Sept 2015
    8.8
    High

    CVE-2015-7801

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file.

    Published: 16 Sept 2015
    Unknown

    CVE-2015-5197

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 15 Sept 2015
    9.3
    Critical

    CVE-2015-6946

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary code via the (1) akey or (2) actserver parameter to the activate_doit function or (3) licfile parameter to the service_startup_doit functionality.

    Published: 15 Sept 2015
    7.8
    High

    CVE-2015-5472

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in lib/download.php in the IBS Mappro plugin before 1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter.

    Published: 15 Sept 2015
    Unknown

    CVE-2015-6947

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-6946. Reason: This issue was MERGED into CVE-2015-6946 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2015-6946 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Sept 2015
    6
    Medium

    CVE-2015-6943

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the serendipity_checkCommentToken function in include/functions_comments.inc.php in Serendipity before 2.0.2, when "Use Tokens for Comment Moderation" is enabled, allows remote administrators to execute arbitrary SQL commands via the serendipity[id] parameter to serendipity_admin.php.

    Published: 15 Sept 2015