CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2015-2479

    Last Modified: 12 Apr 2025

    The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote attackers to execute arbitrary code via a crafted .NET application, aka "RyuJIT Optimization Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2480 and CVE-2015-2481.

    Published: 15 Aug 2015
    9.3
    Critical

    CVE-2015-2431

    Last Modified: 12 Apr 2025

    Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Library (OGL) font, aka "Microsoft Office Graphics Component Remote Code Execution Vulnerability."

    Published: 15 Aug 2015
    9.3
    Critical

    CVE-2015-2432

    Last Modified: 12 Apr 2025

    ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."

    Published: 15 Aug 2015
    2.1
    Low

    CVE-2015-2433

    Last Modified: 12 Apr 2025

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability."

    Published: 15 Aug 2015
    4.3
    Medium

    CVE-2015-2434

    Last Modified: 12 Apr 2025

    Microsoft XML Core Services 3.0 and 5.0 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and conducting a decryption attack, aka "MSXML Information Disclosure Vulnerability," a different vulnerability than CVE-2015-2471.

    Published: 15 Aug 2015
    9.3
    Critical

    CVE-2015-2458

    Last Modified: 12 Apr 2025

    ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2459 and CVE-2015-2461.

    Published: 15 Aug 2015
    9.3
    Critical

    CVE-2015-2462

    Last Modified: 12 Apr 2025

    ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."

    Published: 15 Aug 2015
    9.3
    Critical

    CVE-2015-2464

    Last Modified: 12 Apr 2025

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allow remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2463.

    Published: 15 Aug 2015
    9.3
    Critical

    CVE-2015-2467

    Last Modified: 12 Apr 2025

    Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 15 Aug 2015
    9.3
    Critical

    CVE-2015-2469

    Last Modified: 12 Apr 2025

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, and Office for Mac 2011 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 15 Aug 2015
    9.3
    Critical

    CVE-2015-2470

    Last Modified: 12 Apr 2025

    Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 2011, and Word Viewer allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Integer Underflow Vulnerability."

    Published: 15 Aug 2015
    4.3
    Medium

    CVE-2015-2471

    Last Modified: 12 Apr 2025

    Microsoft XML Core Services 3.0, 5.0, and 6.0 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and conducting a decryption attack, aka "MSXML Information Disclosure Vulnerability," a different vulnerability than CVE-2015-2434.

    Published: 15 Aug 2015
    9
    Critical

    CVE-2015-2474

    Last Modified: 12 Apr 2025

    Microsoft Windows Vista SP2 and Server 2008 SP2 allow remote authenticated users to execute arbitrary code via a crafted string in a Server Message Block (SMB) server error-logging action, aka "Server Message Block Memory Corruption Vulnerability."

    Published: 15 Aug 2015
    4.3
    Medium

    CVE-2015-2475

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in uddi/search/frames.aspx in the UDDI Services component in Microsoft Windows Server 2008 SP2 and BizTalk Server 2010, 2013 Gold, and 2013 R2 allows remote attackers to inject arbitrary web script or HTML via the search parameter, aka "UDDI Services Elevation of Privilege Vulnerability."

    Published: 15 Aug 2015
    9.3
    Critical

    CVE-2015-2477

    Last Modified: 12 Apr 2025

    Microsoft Office 2007 SP3, Office for Mac 2011, Office for Mac 2016, and Word Viewer allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 15 Aug 2015
    9.3
    Critical

    CVE-2015-2480

    Last Modified: 12 Apr 2025

    The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote attackers to execute arbitrary code via a crafted .NET application, aka "RyuJIT Optimization Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2479 and CVE-2015-2481.

    Published: 15 Aug 2015
    9.3
    Critical

    CVE-2015-2481

    Last Modified: 12 Apr 2025

    The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote attackers to execute arbitrary code via a crafted .NET application, aka "RyuJIT Optimization Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2479 and CVE-2015-2480.

    Published: 15 Aug 2015
    7.5
    High

    CVE-2015-8746

    Last Modified: 12 Apr 2025

    fs/nfs/nfs4proc.c in the NFS client in the Linux kernel before 4.2.2 does not properly initialize memory for migration recovery operations, which allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) via crafted network traffic.

    Published: 15 Aug 2015
    4.3
    Medium

    CVE-2015-5475

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Request Tracker (RT) 4.x before 4.2.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) user and (2) group rights management pages.

    Published: 14 Aug 2015
    5
    Medium

    CVE-2015-5696

    Last Modified: 12 Apr 2025

    Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.

    Published: 14 Aug 2015
    9.3
    Critical

    CVE-2015-2442

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 through 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2444.

    Published: 14 Aug 2015
    9.3
    Critical

    CVE-2015-2447

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2446.

    Published: 14 Aug 2015
    4.3
    Medium

    CVE-2015-2449

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 through 11 and Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "ASLR Bypass."

    Published: 14 Aug 2015
    9.3
    Critical

    CVE-2015-2441

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 through 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2452.

    Published: 14 Aug 2015
    9.3
    Critical

    CVE-2015-2446

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2447.

    Published: 14 Aug 2015
    9.3
    Critical

    CVE-2015-2448

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."

    Published: 14 Aug 2015
    4.3
    Medium

    CVE-2015-2445

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 10 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "ASLR Bypass."

    Published: 14 Aug 2015
    9.3
    Critical

    CVE-2015-2443

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."

    Published: 14 Aug 2015
    9.3
    Critical

    CVE-2015-2444

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2442.

    Published: 14 Aug 2015
    9.3
    Critical

    CVE-2015-2450

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2451.

    Published: 14 Aug 2015
    9.3
    Critical

    CVE-2015-2451

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2450.

    Published: 14 Aug 2015
    9.3
    Critical

    CVE-2015-2452

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2441.

    Published: 14 Aug 2015
    6.1
    Medium

    CVE-2017-0363

    Last Modified: 21 Nov 2024

    Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.

    Published: 14 Aug 2015
    4.3
    Medium

    CVE-2015-4665

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.

    Published: 13 Aug 2015
    9.3
    Critical

    CVE-2015-5474

    Last Modified: 12 Apr 2025

    BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol.

    Published: 13 Aug 2015
    4.3
    Medium

    CVE-2015-5535

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the qTranslate plugin 2.5.39 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the edit parameter in the qtranslate page to wp-admin/options-general.php.

    Published: 13 Aug 2015
    9
    Critical

    CVE-2015-5536

    Last Modified: 12 Apr 2025

    Belkin N300 Dual-Band Wi-Fi Range Extender with firmware before 1.04.10 allows remote authenticated users to execute arbitrary commands via the (1) sub_dir parameter in a formUSBStorage request; pinCode parameter in a (2) formWpsStart or (3) formiNICWpsStart request; (4) wps_enrolee_pin parameter in a formWlanSetupWPS request; or unspecified parameters in a (5) formWlanMP, (6) formBSSetSitesurvey, (7) formHwSet, or (8) formConnectionSetting request.

    Published: 13 Aug 2015
    7.5
    High

    CVE-2015-5685

    Last Modified: 12 Apr 2025

    The lazy_bdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) allows remote attackers to execute arbitrary code via a crafted packet, related to "improper indexing."

    Published: 13 Aug 2015
    4.3
    Medium

    CVE-2015-2321

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the email field.

    Published: 13 Aug 2015
    5
    Medium

    CVE-2015-4666

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.

    Published: 13 Aug 2015
    3.5
    Low

    CVE-2015-5163

    Last Modified: 12 Apr 2025

    The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image.

    Published: 13 Aug 2015
    5.3
    Medium

    CVE-2015-5186

    Last Modified: 20 Apr 2025

    Audit before 2.4.4 in Linux does not sanitize escape characters in filenames.

    Published: 13 Aug 2015
    4.6
    Medium

    CVE-2015-1334

    Last Modified: 12 Apr 2025

    attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confinement by mounting a proc filesystem with a crafted (1) AppArmor profile or (2) SELinux label.

    Published: 12 Aug 2015
    4
    Medium

    CVE-2015-5718

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the handle_debug_network function in the manager in Websense Content Gateway before 8.0.0 HF02 allows remote administrators to cause a denial of service (crash) via a crafted diagnostic command line request to submit_net_debug.cgi.

    Published: 12 Aug 2015
    4.3
    Medium

    CVE-2015-3282

    Last Modified: 12 Apr 2025

    vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.

    Published: 12 Aug 2015
    2.1
    Low

    CVE-2015-3285

    Last Modified: 12 Apr 2025

    The pioctl for the OSD FS command in OpenAFS before 1.6.13 uses the wrong pointer when writing the results of the RPC, which allows local users to cause a denial of service (memory corruption and kernel panic) via a crafted OSD FS command.

    Published: 12 Aug 2015
    4.9
    Medium

    CVE-2015-1331

    Last Modified: 12 Apr 2025

    lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.

    Published: 12 Aug 2015
    6.8
    Medium

    CVE-2015-3283

    Last Modified: 12 Apr 2025

    OpenAFS before 1.6.13 allows remote attackers to spoof bos commands via unspecified vectors.

    Published: 12 Aug 2015
    2.1
    Low

    CVE-2015-3284

    Last Modified: 12 Apr 2025

    pioctls in OpenAFS 1.6.x before 1.6.13 allows local users to read kernel memory via crafted commands.

    Published: 12 Aug 2015
    4.6
    Medium

    CVE-2015-3286

    Last Modified: 12 Apr 2025

    Buffer overflow in the Solaris kernel extension in OpenAFS before 1.6.13 allows local users to cause a denial of service (panic or deadlock) or possibly have other unspecified impact via a large group list when joining a PAG.

    Published: 12 Aug 2015