CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-6915

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Montala Limited ResourceSpace 7.3.7009 and earlier allows remote attackers to execute arbitrary SQL commands via the "user" cookie to plugins/feedback/pages/feedback.php.

    Published: 11 Sept 2015
    4.3
    Medium

    CVE-2015-6584

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php.

    Published: 11 Sept 2015
    6.8
    Medium

    CVE-2015-6827

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests that change a password via a request to signup.php.

    Published: 11 Sept 2015
    Unknown

    CVE-2015-5249

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 10 Sept 2015
    5.9
    Medium

    CVE-2015-7315

    Last Modified: 20 Apr 2025

    Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registration enabled, without acknowledgment of site administrator.

    Published: 10 Sept 2015
    5.5
    Medium

    CVE-2016-0821

    Last Modified: 12 Apr 2025

    The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a poison-pointer protection mechanism by triggering the use of an uninitialized list entry, aka Android internal bug 26186802, a different vulnerability than CVE-2015-3636.

    Published: 10 Sept 2015
    5.3
    Medium

    CVE-2013-7446

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel before 4.3.3 allows local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls.

    Published: 10 Sept 2015
    6.1
    Medium

    CVE-2015-7316

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x before 4.3.7, and 5.0rc1.

    Published: 10 Sept 2015
    6.8
    Medium

    CVE-2015-7317

    Last Modified: 20 Apr 2025

    Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 allows remote authenticated users to edit Kupu settings.

    Published: 10 Sept 2015
    7.5
    High

    CVE-2015-7318

    Last Modified: 20 Apr 2025

    Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.

    Published: 10 Sept 2015
    8.2
    High

    CVE-2015-2546

    Last Modified: 22 Apr 2026

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.

    Published: 9 Sept 2015
    7.8
    High

    CVE-2015-2545

    Last Modified: 22 Apr 2026

    Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2542

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2541

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2485 and CVE-2015-2491.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2487

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2490, CVE-2015-2492, CVE-2015-2494, CVE-2015-2498, and CVE-2015-2499.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2490

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2487, CVE-2015-2492, CVE-2015-2494, CVE-2015-2498, and CVE-2015-2499.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2498

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2487, CVE-2015-2490, CVE-2015-2492, CVE-2015-2494, and CVE-2015-2499.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2499

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2487, CVE-2015-2490, CVE-2015-2492, CVE-2015-2494, and CVE-2015-2498.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2506

    Last Modified: 12 Apr 2025

    atmfd.dll in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to cause a denial of service (system crash) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."

    Published: 9 Sept 2015
    7.2
    High

    CVE-2015-2508

    Last Modified: 12 Apr 2025

    The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of Privilege Vulnerability."

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2510

    Last Modified: 12 Apr 2025

    Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 SP3, Office 2010 SP2, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "Graphics Component Buffer Overflow Vulnerability."

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2519

    Last Modified: 12 Apr 2025

    Integer overflow in Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted .jnt file, aka "Windows Journal Integer Overflow RCE Vulnerability."

    Published: 9 Sept 2015
    7.2
    High

    CVE-2015-2527

    Last Modified: 12 Apr 2025

    The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

    Published: 9 Sept 2015
    7.2
    High

    CVE-2015-2528

    Last Modified: 12 Apr 2025

    Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2524.

    Published: 9 Sept 2015
    1.9
    Low

    CVE-2015-2534

    Last Modified: 12 Apr 2025

    Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL settings, which allows local users to bypass intended network-traffic restrictions via a crafted application, aka "Hyper-V Security Feature Bypass Vulnerability."

    Published: 9 Sept 2015
    4.3
    Medium

    CVE-2015-2543

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, aka "Exchange Spoofing Vulnerability."

    Published: 9 Sept 2015
    10
    Critical

    CVE-2015-6681

    Last Modified: 12 Apr 2025

    Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6680.

    Published: 9 Sept 2015
    7.5
    High

    CVE-2015-6855

    Last Modified: 12 Apr 2025

    hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.

    Published: 9 Sept 2015
    4.3
    Medium

    CVE-2015-2489

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 11 allows remote attackers to gain privileges via a crafted web site, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Elevation of Privilege Vulnerability."

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2500

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."

    Published: 9 Sept 2015
    7.2
    High

    CVE-2015-2507

    Last Modified: 12 Apr 2025

    The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2512.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2513

    Last Modified: 12 Apr 2025

    Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted .jnt file, aka "Windows Journal RCE Vulnerability," a different vulnerability than CVE-2015-2514 and CVE-2015-2530.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2514

    Last Modified: 12 Apr 2025

    Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted .jnt file, aka "Windows Journal RCE Vulnerability," a different vulnerability than CVE-2015-2513 and CVE-2015-2530.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2520

    Last Modified: 12 Apr 2025

    Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 9 Sept 2015
    7.2
    High

    CVE-2015-2524

    Last Modified: 12 Apr 2025

    Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2528.

    Published: 9 Sept 2015
    2.1
    Low

    CVE-2015-2529

    Last Modified: 12 Apr 2025

    The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability."

    Published: 9 Sept 2015
    4
    Medium

    CVE-2015-2535

    Last Modified: 12 Apr 2025

    Active Directory in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service outage) by creating multiple machine accounts, aka "Active Directory Denial of Service Vulnerability."

    Published: 9 Sept 2015
    4.3
    Medium

    CVE-2015-2544

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, aka "Exchange Spoofing Vulnerability."

    Published: 9 Sept 2015
    10
    Critical

    CVE-2015-6680

    Last Modified: 12 Apr 2025

    Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6681.

    Published: 9 Sept 2015
    5
    Medium

    CVE-2015-6908

    Last Modified: 12 Apr 2025

    The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2491

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2485 and CVE-2015-2541.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2492

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2487, CVE-2015-2490, CVE-2015-2494, CVE-2015-2498, and CVE-2015-2499.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2485

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2491 and CVE-2015-2541.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2486

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2487, CVE-2015-2490, CVE-2015-2492, CVE-2015-2494, CVE-2015-2498, and CVE-2015-2499.

    Published: 9 Sept 2015
    5
    Medium

    CVE-2015-2483

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Information Disclosure Vulnerability."

    Published: 9 Sept 2015
    6.4
    Medium

    CVE-2015-2484

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 10 and 11 uses an incorrect flag during certain filesystem accesses, which allows remote attackers to delete arbitrary files via unspecified vectors, aka "Tampering Vulnerability."

    Published: 9 Sept 2015
    5
    Medium

    CVE-2015-2526

    Last Modified: 12 Apr 2025

    Microsoft .NET Framework 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to cause a denial of service to an ASP.NET web site via crafted requests, aka "MVC Denial of Service Vulnerability."

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2493

    Last Modified: 12 Apr 2025

    The (1) VBScript and (2) JScript engines in Microsoft Internet Explorer 8 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2494

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-2015-2487, CVE-2015-2490, CVE-2015-2492, CVE-2015-2498, and CVE-2015-2499.

    Published: 9 Sept 2015
    9.3
    Critical

    CVE-2015-2501

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."

    Published: 9 Sept 2015