CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2015-1171

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in GSM SIM Utility (aka SIM Card Editor) 6.6 allows remote attackers to execute arbitrary code via a long entry in a .sms file.

    Published: 28 Aug 2015
    2.6
    Low

    CVE-2015-2987

    Last Modified: 12 Apr 2025

    Type74 ED before 4.0 misuses 128-bit ECB encryption for small files, which makes it easier for attackers to obtain plaintext data via differential cryptanalysis of a file with an original length smaller than 128 bits.

    Published: 28 Aug 2015
    5
    Medium

    CVE-2015-6266

    Last Modified: 12 Apr 2025

    The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote attackers to obtain sensitive information from customized documents via a direct request, aka Bug ID CSCuo78045.

    Published: 28 Aug 2015
    6.9
    Medium

    CVE-2015-5367

    Last Modified: 12 Apr 2025

    The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows local users to gain privileges via unspecified vectors.

    Published: 27 Aug 2015
    7.8
    High

    CVE-2015-5368

    Last Modified: 12 Apr 2025

    The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows remote attackers to modify data or cause a denial of service, or execute arbitrary code, via unspecified vectors.

    Published: 27 Aug 2015
    4
    Medium

    CVE-2015-2139

    Last Modified: 12 Apr 2025

    HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-5403.

    Published: 27 Aug 2015
    6.5
    Medium

    CVE-2015-5405

    Last Modified: 12 Apr 2025

    HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.

    Published: 27 Aug 2015
    4.3
    Medium

    CVE-2015-6265

    Last Modified: 12 Apr 2025

    The CLI in Cisco Application Control Engine (ACE) 4700 A5 3.0 and earlier allows local users to bypass intended access restrictions, and read or write to files, by entering an unspecified CLI command with a crafted file as this command's input, aka Bug ID CSCur23662.

    Published: 27 Aug 2015
    6.5
    Medium

    CVE-2015-2140

    Last Modified: 12 Apr 2025

    HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

    Published: 27 Aug 2015
    7.2
    High

    CVE-2015-5402

    Last Modified: 12 Apr 2025

    HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows local users to gain privileges, and consequently obtain sensitive information, modify data, or cause a denial of service, via unspecified vectors.

    Published: 27 Aug 2015
    4
    Medium

    CVE-2015-5403

    Last Modified: 12 Apr 2025

    HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2015-2139.

    Published: 27 Aug 2015
    7.5
    High

    CVE-2015-5404

    Last Modified: 12 Apr 2025

    HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

    Published: 27 Aug 2015
    7.5
    High

    CVE-2015-5427

    Last Modified: 12 Apr 2025

    HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2015-5428 and CVE-2015-5429.

    Published: 27 Aug 2015
    7.5
    High

    CVE-2015-5429

    Last Modified: 12 Apr 2025

    HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2015-5427 and CVE-2015-5428.

    Published: 27 Aug 2015
    5
    Medium

    CVE-2015-5430

    Last Modified: 12 Apr 2025

    HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 27 Aug 2015
    6.5
    Medium

    CVE-2015-5431

    Last Modified: 12 Apr 2025

    HP Matrix Operating Environment before 7.5.0 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

    Published: 27 Aug 2015
    7.5
    High

    CVE-2015-5432

    Last Modified: 12 Apr 2025

    HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

    Published: 27 Aug 2015
    4
    Medium

    CVE-2015-5433

    Last Modified: 12 Apr 2025

    HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 27 Aug 2015
    7.5
    High

    CVE-2015-5428

    Last Modified: 12 Apr 2025

    HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2015-5427 and CVE-2015-5429.

    Published: 27 Aug 2015
    7.5
    High

    CVE-2015-4498

    Last Modified: 12 Apr 2025

    The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

    Published: 27 Aug 2015
    4.2
    Medium

    CVE-2015-5233

    Last Modified: 12 Apr 2025

    Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to delete reports from arbitrary hosts via direct access to the (a) individual report show/delete pages or (b) APIs.

    Published: 27 Aug 2015
    8.8
    High

    CVE-2015-5237

    Last Modified: 20 Apr 2025

    protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.

    Published: 27 Aug 2015
    10
    Critical

    CVE-2015-4497

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

    Published: 27 Aug 2015
    6.1
    Medium

    CVE-2015-6748

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.

    Published: 27 Aug 2015
    6.9
    Medium

    CVE-2015-4173

    Last Modified: 12 Apr 2025

    Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.

    Published: 26 Aug 2015
    7.5
    High

    CVE-2015-5409

    Last Modified: 12 Apr 2025

    Buffer overflow in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.

    Published: 26 Aug 2015
    6.5
    Medium

    CVE-2015-5410

    Last Modified: 12 Apr 2025

    HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to execute arbitrary code or cause a denial of service via unspecified vectors.

    Published: 26 Aug 2015
    6.8
    Medium

    CVE-2015-5411

    Last Modified: 12 Apr 2025

    HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 26 Aug 2015
    6
    Medium

    CVE-2015-5412

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

    Published: 26 Aug 2015
    4
    Medium

    CVE-2015-5413

    Last Modified: 12 Apr 2025

    HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to gain privileges and obtain sensitive information via unspecified vectors.

    Published: 26 Aug 2015
    4
    Medium

    CVE-2015-6261

    Last Modified: 12 Apr 2025

    Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read configuration files by leveraging the Mobile and Remote Access (MRA) role and establishing a TFTP session, aka Bug ID CSCuv78531.

    Published: 26 Aug 2015
    6.1
    Medium

    CVE-2015-2992

    Last Modified: 21 Nov 2024

    Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.

    Published: 26 Aug 2015
    6.1
    Medium

    CVE-2015-5169

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.

    Published: 26 Aug 2015
    5
    Medium

    CVE-2015-5223

    Last Modified: 12 Apr 2025

    OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that references an object in another container.

    Published: 26 Aug 2015
    5
    Medium

    CVE-2015-7995

    Last Modified: 12 Apr 2025

    The xsltStylePreCompute function in preproc.c in libxslt 1.1.28 does not check if the parent node is an element, which allows attackers to cause a denial of service via a crafted XML file, related to a "type confusion" issue.

    Published: 26 Aug 2015
    6.8
    Medium

    CVE-2015-5161

    Last Modified: 12 Apr 2025

    The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.

    Published: 25 Aug 2015
    6.8
    Medium

    CVE-2015-5949

    Last Modified: 12 Apr 2025

    VideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP file, which triggers the freeing of arbitrary pointers.

    Published: 25 Aug 2015
    5
    Medium

    CVE-2015-3269

    Last Modified: 12 Apr 2025

    Apache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4.6.2 before 4.6.2.354169, and 4.7 before 4.7.0.354169 and other products, allows remote attackers to read arbitrary files via an AMF message containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 25 Aug 2015
    6.8
    Medium

    CVE-2015-5785

    Last Modified: 12 Apr 2025

    Apple QuickTime before 7.7.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-5786.

    Published: 25 Aug 2015
    6.8
    Medium

    CVE-2015-5786

    Last Modified: 12 Apr 2025

    Apple QuickTime before 7.7.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-5785.

    Published: 25 Aug 2015
    6.8
    Medium

    CVE-2015-6262

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cisco Prime Infrastructure 1.2(0.103) and 2.0(0.0) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCum49054 and CSCum49059.

    Published: 25 Aug 2015
    4.3
    Medium

    CVE-2015-3240

    Last Modified: 12 Apr 2025

    The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.

    Published: 25 Aug 2015
    7.5
    High

    CVE-2015-5219

    Last Modified: 20 Apr 2025

    The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.

    Published: 25 Aug 2015
    4.3
    Medium

    CVE-2014-9767

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the ZipArchive::extractTo function in ext/zip/php_zip.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 and ext/zip/ext_zip.cpp in HHVM before 3.12.1 allows remote attackers to create arbitrary empty directories via a crafted ZIP archive.

    Published: 25 Aug 2015
    7.5
    High

    CVE-2015-5194

    Last Modified: 20 Apr 2025

    The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.

    Published: 25 Aug 2015
    7.5
    High

    CVE-2015-5195

    Last Modified: 20 Apr 2025

    ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation.

    Published: 25 Aug 2015
    7.8
    High

    CVE-2015-5228

    Last Modified: 12 Apr 2025

    The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing files via unspecified vectors related to a directory path.

    Published: 25 Aug 2015
    5.5
    Medium

    CVE-2015-5231

    Last Modified: 12 Apr 2025

    The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access.

    Published: 25 Aug 2015
    7.5
    High

    CVE-2015-7703

    Last Modified: 20 Apr 2025

    The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.

    Published: 25 Aug 2015
    7.5
    High

    CVE-2015-5419

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP KeyView before 10.23.0.1 and 10.24.x before 10.24.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2879.

    Published: 24 Aug 2015