CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2015-6944

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for requests that execute arbitrary SQL commands via the cmd parameter to sys/sys/listaBD2.jsp.

    Published: 15 Sept 2015
    4.3
    Medium

    CVE-2015-6945

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to inject arbitrary web script or HTML via the bd parameter to sys/sys/listaBD2.jsp.

    Published: 15 Sept 2015
    6.8
    Medium

    CVE-2015-6948

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the Microsoft Word document conversion feature in Corel WordPerfect allows remote attackers to execute arbitrary code via a crafted document.

    Published: 15 Sept 2015
    9.3
    Critical

    CVE-2015-6949

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the ASUS TM-AC1900 router allows remote attackers to execute arbitrary code via crafted HTTP header values.

    Published: 15 Sept 2015
    9
    Critical

    CVE-2015-4947

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the Administration Server in IBM HTTP Server 6.1.0.x through 6.1.0.47, 7.0.0.x before 7.0.0.39, 8.0.0.x before 8.0.0.12, and 8.5.x before 8.5.5.7, as used in WebSphere Application Server and other products, allows remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 15 Sept 2015
    7.5
    High

    CVE-2015-5201

    Last Modified: 21 Nov 2024

    VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to log in without authentication via unspecified vectors.

    Published: 15 Sept 2015
    7.2
    High

    CVE-2015-5279

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via vectors related to receiving packets.

    Published: 15 Sept 2015
    9.8
    Critical

    CVE-2015-5244

    Last Modified: 20 Apr 2025

    The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass application restrictions.

    Published: 15 Sept 2015
    6.5
    Medium

    CVE-2015-5278

    Last Modified: 21 Nov 2024

    The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.

    Published: 15 Sept 2015
    9.8
    Critical

    CVE-2015-8871

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors.

    Published: 15 Sept 2015
    4
    Medium

    CVE-2015-4980

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in IBM WebSphere Commerce 7.0.0.6 through 7.0.0.9 allows remote authenticated users to obtain sensitive personal information via unknown vectors.

    Published: 14 Sept 2015
    7.8
    High

    CVE-2015-1943

    Last Modified: 12 Apr 2025

    IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

    Published: 14 Sept 2015
    7.8
    High

    CVE-2015-5997

    Last Modified: 12 Apr 2025

    Impero Education Pro before 5105 uses a hardcoded CBC key and initialization vector derived from a hash of the Imp3ro string, which makes it easier for remote attackers to obtain plaintext data by sniffing the network for ciphertext data.

    Published: 14 Sept 2015
    10
    Critical

    CVE-2015-5998

    Last Modified: 12 Apr 2025

    Impero Education Pro before 5105 relies on the -1|AUTHENTICATE\x02PASSWORD string for authentication, which allows remote attackers to execute arbitrary programs via an encrypted command.

    Published: 14 Sept 2015
    6.4
    Medium

    CVE-2015-6285

    Last Modified: 12 Apr 2025

    Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or service outage) via format string specifiers in an HTTP request, aka Bug ID CSCug21497.

    Published: 14 Sept 2015
    7.5
    High

    CVE-2015-4499

    Last Modified: 12 Apr 2025

    Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain name by placing that name in a substring of an address, as demonstrated by truncation of an @mozilla.com.example.com address to an @mozilla.com address.

    Published: 14 Sept 2015
    5.7
    Medium

    CVE-2015-6286

    Last Modified: 12 Apr 2025

    Cisco Application Visibility and Control (AVC) 15.3(3)JA, when FlexConnect is enabled, allows remote attackers to cause a denial of service (access-point outage) via a crafted UDP packet, aka Bug ID CSCuu47016.

    Published: 14 Sept 2015
    5
    Medium

    CVE-2015-2013

    Last Modified: 12 Apr 2025

    IBM WebSphere MQ 7.0.1 before 7.0.1.13 allows remote attackers to cause a denial of service (channel-agent abend and process outage) via a crafted selection string in an MQI call.

    Published: 14 Sept 2015
    5
    Medium

    CVE-2015-6287

    Last Modified: 12 Apr 2025

    Cisco Web Security Appliance (WSA) 8.0.6-078 and 8.0.6-115 allows remote attackers to cause a denial of service (service outage) via a flood of TCP traffic that leads to DNS resolution delays, aka Bug IDs CSCur32005 and CSCur07907.

    Published: 14 Sept 2015
    5
    Medium

    CVE-2015-6288

    Last Modified: 12 Apr 2025

    Cisco Content Security Management Appliance (SMA) 7.8.0-000 does not properly validate credentials, which allows remote attackers to cause a denial of service (rapid log-file rollover and application fault) via crafted HTTP requests, aka Bug ID CSCuw09620.

    Published: 14 Sept 2015
    4.3
    Medium

    CVE-2015-6290

    Last Modified: 12 Apr 2025

    Cisco Web Security Appliance (WSA) 8.0.7 allows remote HTTP servers to cause a denial of service (memory consumption from stale TCP connections) via crafted responses, aka Bug ID CSCuw10426.

    Published: 14 Sept 2015
    5
    Medium

    CVE-2015-6830

    Last Modified: 12 Apr 2025

    libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha.

    Published: 14 Sept 2015
    5
    Medium

    CVE-2015-7940

    Last Modified: 12 Apr 2025

    The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."

    Published: 14 Sept 2015
    5
    Medium

    CVE-2015-2695

    Last Modified: 12 Apr 2025

    lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.

    Published: 14 Sept 2015
    7.2
    High

    CVE-2015-5277

    Last Modified: 12 Apr 2025

    The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.

    Published: 14 Sept 2015
    4.9
    Medium

    CVE-2015-6937

    Last Modified: 12 Apr 2025

    The __rds_conn_create function in net/rds/connection.c in the Linux kernel through 4.2.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by using a socket that was not properly bound.

    Published: 14 Sept 2015
    7.1
    High

    CVE-2015-2696

    Last Modified: 12 Apr 2025

    lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mishandled during a gss_inquire_context call.

    Published: 14 Sept 2015
    9.8
    Critical

    CVE-2016-6288

    Last Modified: 12 Apr 2025

    The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

    Published: 13 Sept 2015
    Unknown

    CVE-2015-5226

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 12 Sept 2015
    Unknown

    CVE-2015-5270

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 12 Sept 2015
    9.8
    Critical

    CVE-2015-6941

    Last Modified: 20 Apr 2025

    win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.

    Published: 12 Sept 2015
    6.8
    Medium

    CVE-2015-5629

    Last Modified: 12 Apr 2025

    The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.

    Published: 11 Sept 2015
    4.3
    Medium

    CVE-2015-5630

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted SSID.

    Published: 11 Sept 2015
    4.3
    Medium

    CVE-2015-6919

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the q parameter to index.php.

    Published: 11 Sept 2015
    4.3
    Medium

    CVE-2015-6920

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in js/window.php in the sourceAFRICA plugin 0.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.

    Published: 11 Sept 2015
    9.3
    Critical

    CVE-2014-7216

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or (2) title keys in an emoticons.xml file.

    Published: 11 Sept 2015
    2.6
    Low

    CVE-2015-6921

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Sept 2015
    4.3
    Medium

    CVE-2015-6675

    Last Modified: 12 Apr 2025

    Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation protection mechanism via IP traffic.

    Published: 11 Sept 2015
    10
    Critical

    CVE-2014-9208

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attackers to execute arbitrary code via unknown vectors.

    Published: 11 Sept 2015
    8.5
    High

    CVE-2015-6464

    Last Modified: 12 Apr 2025

    The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to bypass a read-only protection mechanism by using Firefox with a web-developer plugin.

    Published: 11 Sept 2015
    4.3
    Medium

    CVE-2015-6909

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the "Create download task via file upload" feature in Synology Download Station before 3.5-2962 allows remote attackers to inject arbitrary web script or HTML via the name element in the Info dictionary in a torrent file.

    Published: 11 Sept 2015
    10
    Critical

    CVE-2015-3964

    Last Modified: 12 Apr 2025

    SMA Solar Sunny WebBox has hardcoded passwords, which makes it easier for remote attackers to obtain access via unspecified vectors.

    Published: 11 Sept 2015
    6.8
    Medium

    CVE-2015-5631

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Remote UI on Canon PIXMA MG7500 printers allows remote attackers to hijack the authentication of administrators.

    Published: 11 Sept 2015
    6.8
    Medium

    CVE-2015-6465

    Last Modified: 12 Apr 2025

    The GoAhead web server on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to cause a denial of service (reboot) via a crafted URL.

    Published: 11 Sept 2015
    4.3
    Medium

    CVE-2015-6466

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Diagnosis Ping feature in the administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote attackers to inject arbitrary web script or HTML via an unspecified field.

    Published: 11 Sept 2015
    7.5
    High

    CVE-2015-6910

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands via the id parameter to audiotrack.cgi.

    Published: 11 Sept 2015
    7.5
    High

    CVE-2015-6911

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter to watchstatus.cgi.

    Published: 11 Sept 2015
    10
    Critical

    CVE-2015-6912

    Last Modified: 12 Apr 2025

    Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.

    Published: 11 Sept 2015
    4.3
    Medium

    CVE-2015-6913

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the "Create download task via URL" feature in Synology Download Station before 3.5-2967 allows remote attackers to inject arbitrary web script or HTML via the urls parameter in an add_url_task action to dlm/downloadman.cgi.

    Published: 11 Sept 2015
    7.8
    High

    CVE-2015-6914

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in SiteFactory CMS 5.5.9 allows remote attackers to read arbitrary files via a full pathname in the file parameter to assets/download.aspx.

    Published: 11 Sept 2015