CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2015-3438

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.

    Published: 5 Aug 2015
    3.3
    Low

    CVE-2015-2877

    Last Modified: 20 Apr 2025

    Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplication." Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilities

    Published: 5 Aug 2015
    5
    Medium

    CVE-2015-3184

    Last Modified: 12 Apr 2025

    mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.

    Published: 5 Aug 2015
    4
    Medium

    CVE-2015-3187

    Last Modified: 12 Apr 2025

    The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.

    Published: 5 Aug 2015
    10
    Critical

    CVE-2013-7405

    Last Modified: 12 Apr 2025

    The Ad Hoc Reporting feature in GE Healthcare Centricity DMS 4.2 has a password of Never!Mind for the Administrator user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2006-7253

    Last Modified: 12 Apr 2025

    GE Healthcare Infinia II has a default password of (1) infinia for the infinia user, (2) #bigguy1 for the acqservice user, (3) dont4get2 for the Administrator user, (4) #bigguy1 for the emergency user, and (5) 2Bfamous for the InfiniaAdmin user, which has unspecified impact and attack vectors.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2010-5308

    Last Modified: 12 Apr 2025

    GE Healthcare Optima MR360 does not require authentication for the HIPAA emergency login procedure, which allows physically proximate users to gain access via an arbitrary username in the Emergency Login screen. NOTE: this might not qualify for inclusion in CVE if unauthenticated emergency access is part of the intended security policy of the product, can be controlled by the system administrator, and is not enabled by default.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2010-5309

    Last Modified: 12 Apr 2025

    GE Healthcare CADStream Server has a default password of confirma for the admin user, which has unspecified impact and attack vectors.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2010-5310

    Last Modified: 12 Apr 2025

    The Acquisition Workstation for the GE Healthcare Revolution XQ/i has a password of adw3.1 for the sdc user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2011-5322

    Last Modified: 12 Apr 2025

    GE Healthcare Centricity Analytics Server 1.1 has a default password of (1) V0yag3r for the SQL Server sa user, (2) G3car3s for the analyst user, (3) G3car3s for the ccg user, (4) V0yag3r for the viewer user, and (5) geservice for the geservice user in the Webmin interface, which has unspecified impact and attack vectors.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2011-5324

    Last Modified: 12 Apr 2025

    The TeraRecon server, as used in GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions, has a password of (1) shared for the shared user and (2) scan for the scan user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2012-6693

    Last Modified: 12 Apr 2025

    GE Healthcare Centricity PACS 4.0 Server has a default password of (1) nasro for the nasro (ReadOnly) user and (2) nasrw for the nasrw (Read/Write) user, which has unspecified impact and attack vectors.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2012-6694

    Last Modified: 12 Apr 2025

    GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1, and Server 4.0, has a password of 2charGE for the geservice account, which has unspecified impact and attack vectors related to TimbuktuPro. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires it.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2012-6695

    Last Modified: 12 Apr 2025

    GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a password of ddpadmin for the ddpadmin user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2013-7404

    Last Modified: 12 Apr 2025

    GE Healthcare Discovery NM 750b has a password of 2getin for the insite account for (1) Telnet and (2) FTP, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2013-7442

    Last Modified: 12 Apr 2025

    GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a password of (1) CANal1 for the Administrator user and (2) iis for the IIS user, which has unspecified impact and attack vectors related to TimbuktuPro. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires it.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2002-2446

    Last Modified: 12 Apr 2025

    GE Healthcare Millennium MG, NC, and MyoSIGHT has a password of insite.genieacq for the insite account that cannot be changed without disabling product functionality for remote InSite support, which has unspecified impact and attack vectors.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2003-1603

    Last Modified: 12 Apr 2025

    GE Healthcare Discovery VH has a default password of (1) interfile for the ftpclient user of the Interfile server or (2) "2" for the LOCAL user of the FTP server for the Codonics printer, which has unspecified impact and attack vectors.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2004-2777

    Last Modified: 12 Apr 2025

    GE Healthcare Centricity Image Vault 3.x has a password of (1) gemnet for the administrator account, (2) webadmin for the webadmin administrator account of the ASACA DVD library, (3) an empty value for the gemsservice account of the Ultrasound Database, and possibly (4) gemnet2002 for the gemnet2002 account of the GEMNet license server, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2007-6757

    Last Modified: 12 Apr 2025

    GE Healthcare Centricity DMS 4.2, 4.1, and 4.0 has a password of Muse!Admin for the Museadmin user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2010-5307

    Last Modified: 12 Apr 2025

    The HIPAA configuration interface in GE Healthcare Optima MR360 has a password of (1) operator for the root account, (2) adw2.0 for the admin account, and (3) adw2.0 for the sdc account, which has unspecified impact and attack vectors. NOTE: it is not clear whether these passwords are default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2011-5323

    Last Modified: 12 Apr 2025

    GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions has a password of A11enda1e for the sa SQL server user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2012-6660

    Last Modified: 12 Apr 2025

    GE Healthcare Precision MPi has a password of (1) orion for the serviceapp user, (2) orion for the clinical operator user, and (3) PlatinumOne for the administrator user, which has unspecified impact and attack vectors. NOTE: it is not clear whether these passwords are default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2001-1594

    Last Modified: 12 Apr 2025

    GE Healthcare eNTEGRA P&R has a password of (1) entegra for the entegra user, (2) passme for the super user of the Polestar/Polestar-i Starlink 4 upgrade, (3) 0 for the entegra user of the Codonics printer FTP service, (4) eNTEGRA for the eNTEGRA P&R user account, (5) insite for the WinVNC Login, and possibly other accounts, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2014-7232

    Last Modified: 12 Apr 2025

    GE Healthcare Discovery XR656 and XR656 G2 has a password of (1) 2getin for the insite user, (2) 4$xray for the xruser user, and (3) #superxr for the root user, which has unspecified impact and attack vectors. NOTE: it is not clear whether these passwords are default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2014-7233

    Last Modified: 12 Apr 2025

    GE Healthcare Precision THUNIS-800+ has a default password of (1) 1973 for the factory default System Utilities menu, (2) TH8740 for installation using TH8740_122_Setup.exe, (3) hrml for "Setup and Activation" using DSASetup, and (4) an empty string for Shutter Configuration, which has unspecified impact and attack vectors. NOTE: since these passwords appear to be used to access functionality during installation, this issue might not cross privilege boundaries and might not be a vulnerability.

    Published: 4 Aug 2015
    Unknown

    CVE-2014-7234

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-7233. Reason: This issue was MERGED into CVE-2014-7233 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2014-7233 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 Aug 2015
    10
    Critical

    CVE-2014-9736

    Last Modified: 12 Apr 2025

    GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key manager and (2) server keystore; (3) keystore_password for the server truststore; and atna for the (4) primary storage database and (5) archive storage database, which has unspecified impact and attack vectors.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2002-2445

    Last Modified: 12 Apr 2025

    GE Healthcare Millennium MG, NC, and MyoSIGHT has a default password of (1) root.genie for the root user, (2) "service." for the service user, (3) admin.genie for the admin user, (4) reboot for the reboot user, and (5) shutdown for the shutdown user, which has unspecified impact and attack vectors.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2009-5143

    Last Modified: 12 Apr 2025

    GE Healthcare Discovery 530C has a password of #bigguy1 for the (1) acqservice user and (2) wsservice user of the Xeleris System, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2010-5306

    Last Modified: 12 Apr 2025

    GE Healthcare Optima CT680, CT540, CT640, and CT520 has a default password of #bigguy for the root user, which has unspecified impact and attack vectors.

    Published: 4 Aug 2015
    4.3
    Medium

    CVE-2015-3942

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web-server component in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Aug 2015
    6.9
    Medium

    CVE-2015-3940

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Schneider Electric Wonderware System Platform before 2014 R2 Patch 01 allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 4 Aug 2015
    7.2
    High

    CVE-2015-3959

    Last Modified: 12 Apr 2025

    The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches has a hardcoded serial-console password for a privileged account, which might allow physically proximate attackers to obtain access by establishing a console session to a nonstandard installation on which this account is enabled, and leveraging knowledge of this password.

    Published: 4 Aug 2015
    5.8
    Medium

    CVE-2015-3963

    Last Modified: 12 Apr 2025

    Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x before 7 ipnet_coreip 1.2.2.0, as used on Schneider Electric SAGE RTU devices before J2 and other devices, does not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

    Published: 4 Aug 2015
    4.3
    Medium

    CVE-2015-3960

    Last Modified: 12 Apr 2025

    The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches uses hardcoded RSA private keys and certificates across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms for HTTPS sessions by leveraging knowledge of a private key from another installation.

    Published: 4 Aug 2015
    3.5
    Low

    CVE-2015-3961

    Last Modified: 12 Apr 2025

    The web-server component in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches allows remote authenticated users to cause a denial of service (memory corruption and reboot) via a crafted URL.

    Published: 4 Aug 2015
    5.8
    Medium

    CVE-2015-5176

    Last Modified: 12 Apr 2025

    The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.

    Published: 4 Aug 2015
    7.5
    High

    CVE-2015-8873

    Last Modified: 12 Apr 2025

    Stack consumption vulnerability in Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to cause a denial of service (segmentation fault) via recursive method calls.

    Published: 4 Aug 2015
    9.8
    Critical

    CVE-2015-8876

    Last Modified: 12 Apr 2025

    Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger unintended method execution via crafted serialized data.

    Published: 4 Aug 2015
    3.3
    Low

    CVE-2015-8946

    Last Modified: 12 Apr 2025

    ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.

    Published: 4 Aug 2015
    10
    Critical

    CVE-2015-4931

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4932, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.

    Published: 3 Aug 2015
    7.8
    High

    CVE-2015-1956

    Last Modified: 12 Apr 2025

    IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1958 and CVE-2015-1987.

    Published: 3 Aug 2015
    7.8
    High

    CVE-2015-1958

    Last Modified: 12 Apr 2025

    IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1987.

    Published: 3 Aug 2015
    10
    Critical

    CVE-2015-4932

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.

    Published: 3 Aug 2015
    10
    Critical

    CVE-2015-4933

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4934, and CVE-2015-4935.

    Published: 3 Aug 2015
    10
    Critical

    CVE-2015-4934

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4933, and CVE-2015-4935.

    Published: 3 Aug 2015
    10
    Critical

    CVE-2015-4935

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4932, CVE-2015-4933, and CVE-2015-4934.

    Published: 3 Aug 2015
    5
    Medium

    CVE-2015-4936

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in IBM WebSphere eXtreme Scale 8.6 through 8.6.0.8 allows remote attackers to cause a denial of service via unknown vectors.

    Published: 3 Aug 2015
    7.8
    High

    CVE-2015-1955

    Last Modified: 12 Apr 2025

    IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a crafted byte sequence in authentication data.

    Published: 3 Aug 2015