CVE Feed

    Dashboard / CVE

    4.9
    Medium

    CVE-2015-5189

    Last Modified: 12 Apr 2025

    Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated.

    Published: 1 Sept 2015
    8.5
    High

    CVE-2015-5190

    Last Modified: 12 Apr 2025

    The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL.

    Published: 1 Sept 2015
    2.1
    Low

    CVE-2015-6654

    Last Modified: 12 Apr 2025

    The xenmem_add_to_physmap_one function in arch/arm/mm.c in Xen 4.5.x, 4.4.x, and earlier does not limit the number of printk console messages when reporting a failure to retrieve a reference on a foreign page, which allows remote domains to cause a denial of service by leveraging permissions to map the memory of a foreign guest.

    Published: 1 Sept 2015
    4.3
    Medium

    CVE-2015-1298

    Last Modified: 12 Apr 2025

    The RuntimeEventRouter::OnExtensionUninstalled function in extensions/browser/api/runtime/runtime_api.cc in Google Chrome before 45.0.2454.85 does not ensure that the setUninstallURL preference corresponds to the URL of a web site, which allows user-assisted remote attackers to trigger access to an arbitrary URL via a crafted extension that is uninstalled.

    Published: 1 Sept 2015
    7.5
    High

    CVE-2015-1299

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the shared-timer implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging erroneous timer firing, related to ThreadTimers.cpp and Timer.cpp.

    Published: 1 Sept 2015
    5
    Medium

    CVE-2015-1292

    Last Modified: 12 Apr 2025

    The NavigatorServiceWorker::serviceWorker function in modules/serviceworkers/NavigatorServiceWorker.cpp in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy by accessing a Service Worker.

    Published: 1 Sept 2015
    7.5
    High

    CVE-2015-1293

    Last Modified: 12 Apr 2025

    The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 1 Sept 2015
    5
    Medium

    CVE-2015-1296

    Last Modified: 12 Apr 2025

    The UnescapeURLWithAdjustmentsImpl implementation in net/base/escape.cc in Google Chrome before 45.0.2454.85 does not prevent display of Unicode LOCK characters in the omnibox, which makes it easier for remote attackers to spoof the SSL lock icon by placing one of these characters at the end of a URL, as demonstrated by the omnibox in localizations for right-to-left languages.

    Published: 1 Sept 2015
    7.5
    High

    CVE-2015-1297

    Last Modified: 12 Apr 2025

    The WebRequest API implementation in extensions/browser/api/web_request/web_request_api.cc in Google Chrome before 45.0.2454.85 does not properly consider a request's source before accepting the request, which allows remote attackers to bypass intended access restrictions via a crafted (1) app or (2) extension.

    Published: 1 Sept 2015
    6.8
    Medium

    CVE-2015-3280

    Last Modified: 12 Apr 2025

    OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.

    Published: 1 Sept 2015
    7.8
    High

    CVE-2015-6269

    Last Modified: 12 Apr 2025

    Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted (1) IPv4 or (2) IPv6 packet, aka Bug ID CSCsw69990.

    Published: 31 Aug 2015
    7.8
    High

    CVE-2015-6270

    Last Modified: 12 Apr 2025

    Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted IPv6 packet, aka Bug ID CSCsv98555.

    Published: 31 Aug 2015
    10
    Critical

    CVE-2015-2135

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Intelligent Provisioning 1.00 through 1.62(a), 2.00, and 2.10 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 31 Aug 2015
    7.8
    High

    CVE-2015-6271

    Last Modified: 12 Apr 2025

    Cisco IOS XE 2.1.0 through 2.4.3 and 2.5.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted SIP packet, aka Bug IDs CSCta74749 and CSCta77008.

    Published: 31 Aug 2015
    7.8
    High

    CVE-2015-6272

    Last Modified: 12 Apr 2025

    Cisco IOS XE 2.1.0 through 2.2.3 and 2.3.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted H.323 packet, aka Bug ID CSCsx35393, CSCsx07094, and CSCsw93064.

    Published: 31 Aug 2015
    6.8
    Medium

    CVE-2015-6655

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php.

    Published: 31 Aug 2015
    3.5
    Low

    CVE-2015-6753

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Quick Edit module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) entity title, related to in-place editing, or a (2) node title.

    Published: 31 Aug 2015
    2.1
    Low

    CVE-2015-6754

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the administration interface in the Path Breadcrumbs module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "Administer Path Breadcrumbs" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Aug 2015
    3.5
    Low

    CVE-2015-6751

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Time Tracker module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) note added to a time entry or an (2) activity used to categorize time tracker entries.

    Published: 31 Aug 2015
    3.5
    Low

    CVE-2014-2329

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allow remote authenticated users to inject arbitrary web script or HTML via the (1) agent string for a check_mk agent, a (2) crafted request to a monitored host, which is not properly handled by the logwatch module, or other unspecified vectors.

    Published: 31 Aug 2015
    6.8
    Medium

    CVE-2014-2330

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Multisite GUI in Check_MK before 1.2.5i2 allow remote attackers to hijack the authentication of users for requests that (1) upload arbitrary snapshots, (2) delete arbitrary files, or possibly have other unspecified impact via unknown vectors.

    Published: 31 Aug 2015
    8.5
    High

    CVE-2014-2331

    Last Modified: 12 Apr 2025

    Check_MK 1.2.2p2, 1.2.2p3, and 1.2.3i5 allows remote authenticated users to execute arbitrary Python code via a crafted rules.mk file in a snapshot. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2330.

    Published: 31 Aug 2015
    5.5
    Medium

    CVE-2014-2332

    Last Modified: 12 Apr 2025

    Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, related to "Insecure Direct Object References." NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2330.

    Published: 31 Aug 2015
    4.3
    Medium

    CVE-2014-2570

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in www/make_subset.php in PHP Font Lib before 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Published: 31 Aug 2015
    4.3
    Medium

    CVE-2014-3148

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in libahttp/err.c in OkCupid OKWS (OK Web Server) allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to a non-existent page, which is not properly handled in a 404 error page.

    Published: 31 Aug 2015
    4.3
    Medium

    CVE-2014-6616

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Softing FG-100 PROFIBUS Single Channel (FG-100-PB) with firmware FG-x00-PB_V2.02.0.00 allows remote attackers to inject arbitrary web script or HTML via the DEVICE_NAME parameter to cgi-bin/CFGhttp/.

    Published: 31 Aug 2015
    3.5
    Low

    CVE-2015-6535

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter).

    Published: 31 Aug 2015
    2.1
    Low

    CVE-2015-6752

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Search API Autocomplete module 7.x-1.x before 7.x-1.3 for Drupal, when the search index is configured to use the HTML filter processor, allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in the returned suggestions.

    Published: 31 Aug 2015
    7.5
    High

    CVE-2015-6750

    Last Modified: 12 Apr 2025

    Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command.

    Published: 31 Aug 2015
    6.5
    Medium

    CVE-2015-6742

    Last Modified: 12 Apr 2025

    Basware Banking (Maksuliikenne) before 8.90.07.X uses a hardcoded password for the ANCO account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability types and different affected versions.

    Published: 31 Aug 2015
    4.3
    Medium

    CVE-2015-6744

    Last Modified: 12 Apr 2025

    Basware Banking (Maksuliikenne) before 8.90.07.X relies on the client to enforce (1) login verification, (2) audit trail creation, and (3) account locking, which allows remote attackers to "disrupt security-critical functions" by "dropping network traffic." NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability type and different affected versions.

    Published: 31 Aug 2015
    6.5
    Medium

    CVE-2015-6743

    Last Modified: 12 Apr 2025

    Basware Banking (Maksuliikenne) 8.90.07.X uses a hardcoded password for an unspecified account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability types and different affected versions.

    Published: 31 Aug 2015
    Unknown

    CVE-2015-0942

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-6742, CVE-2015-6743, CVE-2015-6744, CVE-2015-6745, CVE-2015-6746, CVE-2015-6747. Reason: This candidate originally combined multiple issues that have different vulnerability types and other complex abstraction issues. Notes: All CVE users should reference CVE-2015-6742, CVE-2015-6743, CVE-2015-6744, CVE-2015-6745, CVE-2015-6746, and CVE-2015-6747 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Aug 2015
    5.8
    Medium

    CVE-2015-0943

    Last Modified: 12 Apr 2025

    Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryption keys, user credentials, and other sensitive information by sniffing the network or modify this traffic by inserting packets into the client-server data stream.

    Published: 31 Aug 2015
    4.6
    Medium

    CVE-2015-6745

    Last Modified: 12 Apr 2025

    Basware Banking (Maksuliikenne) 8.90.07.X relies on the client to enforce account locking, which allows local users to bypass that security mechanism by deleting the entry from the locking table. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability type and different affected versions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-6744.

    Published: 31 Aug 2015
    2.1
    Low

    CVE-2015-6746

    Last Modified: 12 Apr 2025

    Basware Banking (Maksuliikenne) before 8.90.07.X stores private keys in plaintext in the SQL database, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 due to different vulnerability types.

    Published: 31 Aug 2015
    5
    Medium

    CVE-2015-6747

    Last Modified: 12 Apr 2025

    Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 due to different vulnerability types. NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-6746.

    Published: 31 Aug 2015
    5.8
    Medium

    CVE-2015-5717

    Last Modified: 12 Apr 2025

    The Siemens COMPAS Mobile application before 1.6 for Android does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 31 Aug 2015
    7.2
    High

    CVE-2015-5198

    Last Modified: 12 Apr 2025

    libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privileges via unspecified vectors, related to the VDPAU_DRIVER_PATH environment variable.

    Published: 31 Aug 2015
    7.2
    High

    CVE-2015-5199

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in dlopen in libvdpau before 1.1.1 allows local users to gain privileges via the VDPAU_DRIVER environment variable.

    Published: 31 Aug 2015
    6.3
    Medium

    CVE-2015-5200

    Last Modified: 12 Apr 2025

    The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.

    Published: 31 Aug 2015
    7.5
    High

    CVE-2015-4555

    Last Modified: 12 Apr 2025

    Buffer overflow in the HTTP administrative interface in TIBCO Rendezvous before 8.4.4, Rendezvous Network Server before 1.1.1, Substation ES before 2.9.0, and Messaging Appliance before 8.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors, related to the Rendezvous Daemon (rvd), Routing Daemon (rvrd), Secure Daemon (rvsd), Secure Routing Daemon (rvsrd), Gateway Daemon (rvgd), Daemon Adapter (rvda), Cache (rvcache), Agent (rva), and Relay Agent (rvrad) components.

    Published: 30 Aug 2015
    4
    Medium

    CVE-2015-3966

    Last Modified: 12 Apr 2025

    The IPsec SA establishment process on Innominate mGuard devices with firmware 8.x before 8.1.7 allows remote authenticated users to cause a denial of service (VPN service restart) by leveraging a peer relationship to send a crafted configuration with compression.

    Published: 30 Aug 2015
    7.5
    High

    CVE-2015-5698

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 30 Aug 2015
    4.3
    Medium

    CVE-2015-6749

    Last Modified: 12 Apr 2025

    Buffer overflow in the aiff_open function in oggenc/audio.c in vorbis-tools 1.4.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted AIFF file.

    Published: 30 Aug 2015
    7.8
    High

    CVE-2015-6273

    Last Modified: 12 Apr 2025

    Cisco IOS XE before 3.1.2S on ASR 1000 devices mishandles the automatic setup of Virtual Fragment Reassembly (VFR) by certain firewall and NAT components, which allows remote attackers to cause a denial of service (Embedded Services Processor crash) via crafted IP packets, aka Bug IDs CSCtf87624, CSCte93229, CSCtd19103, and CSCti63623.

    Published: 29 Aug 2015
    7.8
    High

    CVE-2015-6268

    Last Modified: 12 Apr 2025

    Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted IPv4 UDP packet, aka Bug ID CSCsw95482.

    Published: 29 Aug 2015
    7.8
    High

    CVE-2015-6267

    Last Modified: 12 Apr 2025

    Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted L2TP packet, aka Bug IDs CSCsw95722 and CSCsw95496.

    Published: 29 Aug 2015
    7.3
    High

    CVE-2015-6836

    Last Modified: 12 Apr 2025

    The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary code via crafted serialized data that triggers a "type confusion" in the serialize_function_call function.

    Published: 29 Aug 2015
    7.5
    High

    CVE-2014-9651

    Last Modified: 12 Apr 2025

    Buffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and before 5.0 allows attackers to have unspecified impact via a positive START argument to the "substring-index[-ci] procedures."

    Published: 28 Aug 2015