CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2015-4247

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue in customer-controlled software. Notes: none

    Published: 21 Jul 2015
    Unknown

    CVE-2015-4245

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue in customer-controlled software. Notes: none

    Published: 21 Jul 2015
    7.8
    High

    CVE-2015-4283

    Last Modified: 12 Apr 2025

    Cisco Videoscape Policy Resource Manager (PRM) 3.5.4 allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP service outage) via (1) a SYN flood or (2) another type of TCP traffic flood, aka Bug IDs CSCuu35104 and CSCuu35128.

    Published: 21 Jul 2015
    7.5
    High

    CVE-2015-1272

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the GPU process implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging the continued availability of a GPUChannelHost data structure during Blink shutdown, related to content/browser/gpu/browser_gpu_channel_host_factory.cc and content/renderer/render_thread_impl.cc.

    Published: 21 Jul 2015
    6.8
    Medium

    CVE-2015-1282

    Last Modified: 12 Apr 2025

    Multiple use-after-free vulnerabilities in fpdfsdk/src/javascript/Document.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, related to the (1) Document::delay and (2) Document::DoFieldDelay functions.

    Published: 21 Jul 2015
    7.5
    High

    CVE-2015-1289

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 21 Jul 2015
    7.5
    High

    CVE-2015-8978

    Last Modified: 12 Apr 2025

    In Soap Lite (aka the SOAP::Lite extension for Perl) 1.14 and earlier, an example attack consists of defining 10 or more XML entities, each defined as consisting of 10 of the previous entity, with the document consisting of a single instance of the largest entity, which expands to one billion copies of the first entity. The amount of computer memory used for handling an external SOAP call would likely exceed that available to the process parsing the XML.

    Published: 21 Jul 2015
    5
    Medium

    CVE-2015-0851

    Last Modified: 12 Apr 2025

    XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

    Published: 21 Jul 2015
    6.8
    Medium

    CVE-2015-1270

    Last Modified: 12 Apr 2025

    The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file.

    Published: 21 Jul 2015
    6.8
    Medium

    CVE-2015-1271

    Last Modified: 12 Apr 2025

    PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted PDF document that triggers a large memory allocation.

    Published: 21 Jul 2015
    6.8
    Medium

    CVE-2015-1273

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid JPEG2000 data in a PDF document.

    Published: 21 Jul 2015
    9.8
    Critical

    CVE-2015-1276

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in content/browser/indexed_db/indexed_db_backing_store.cc in the IndexedDB implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging an abort action before a certain write operation.

    Published: 21 Jul 2015
    7.5
    High

    CVE-2015-1277

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the accessibility implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging lack of certain validity checks for accessibility-tree data structures.

    Published: 21 Jul 2015
    4.3
    Medium

    CVE-2015-1278

    Last Modified: 12 Apr 2025

    content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted document, as demonstrated by the alert_dialog.pdf document.

    Published: 21 Jul 2015
    7.5
    High

    CVE-2015-1284

    Last Modified: 12 Apr 2025

    The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly check for a page's maximum number of frames, which allows remote attackers to cause a denial of service (invalid count value and use-after-free) or possibly have unspecified other impact via crafted JavaScript code that makes many createElement calls for IFRAME elements.

    Published: 21 Jul 2015
    5
    Medium

    CVE-2015-1285

    Last Modified: 12 Apr 2025

    The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack.

    Published: 21 Jul 2015
    4.3
    Medium

    CVE-2015-1287

    Last Modified: 12 Apr 2025

    Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to core/fetch/CSSStyleSheetResource.cpp.

    Published: 21 Jul 2015
    7.5
    High

    CVE-2015-5159

    Last Modified: 21 Nov 2024

    python-kdcproxy before 0.3.2 allows remote attackers to cause a denial of service via a large POST request.

    Published: 21 Jul 2015
    6.8
    Medium

    CVE-2015-1283

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716.

    Published: 21 Jul 2015
    6.8
    Medium

    CVE-2015-1274

    Last Modified: 12 Apr 2025

    Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user's previous "Always open files of this type" choice, related to download_commands.cc and download_prefs.cc.

    Published: 21 Jul 2015
    4.3
    Medium

    CVE-2015-1275

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browser/UrlUtilities.java in Google Chrome before 44.0.2403.89 on Android allows remote attackers to inject arbitrary web script or HTML via a crafted intent: URL, as demonstrated by a trailing alert(document.cookie);// substring, aka "Universal XSS (UXSS)."

    Published: 21 Jul 2015
    7.5
    High

    CVE-2015-1279

    Last Modified: 12 Apr 2025

    Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via large height and stride values.

    Published: 21 Jul 2015
    7.5
    High

    CVE-2015-1280

    Last Modified: 12 Apr 2025

    SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging access to a renderer process and providing crafted serialized data.

    Published: 21 Jul 2015
    4.3
    Medium

    CVE-2015-1281

    Last Modified: 12 Apr 2025

    core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source.

    Published: 21 Jul 2015
    4.3
    Medium

    CVE-2015-1286

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/v8_context_native_handler.cc in Google Chrome before 44.0.2403.89 allows remote attackers to inject arbitrary web script or HTML by leveraging the lack of a certain V8 context restriction, aka a Blink "Universal XSS (UXSS)."

    Published: 21 Jul 2015
    6.8
    Medium

    CVE-2015-1288

    Last Modified: 12 Apr 2025

    The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file, a related issue to CVE-2015-1263.

    Published: 21 Jul 2015
    4
    Medium

    CVE-2015-2862

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote authenticated users to read arbitrary files via a crafted HTTP request.

    Published: 20 Jul 2015
    4.3
    Medium

    CVE-2015-2863

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 20 Jul 2015
    7.2
    High

    CVE-2015-4279

    Last Modified: 12 Apr 2025

    The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by leveraging access to the subordinate fabric interconnect, aka Bug ID CSCut32778.

    Published: 20 Jul 2015
    8.8
    High

    CVE-2015-2426

    Last Modified: 22 Apr 2026

    Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Driver Vulnerability."

    Published: 20 Jul 2015
    6.9
    Medium

    CVE-2015-2418

    Last Modified: 12 Apr 2025

    Race condition in Microsoft Malicious Software Removal Tool (MSRT) before 5.26 allows local users to gain privileges via a crafted DLL, aka "MSRT Race Condition Vulnerability."

    Published: 20 Jul 2015
    3.5
    Low

    CVE-2015-1922

    Last Modified: 12 Apr 2025

    The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to bypass intended access restrictions and delete table rows via unspecified vectors.

    Published: 20 Jul 2015
    4
    Medium

    CVE-2015-1982

    Last Modified: 12 Apr 2025

    IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message.

    Published: 20 Jul 2015
    4
    Medium

    CVE-2014-8910

    Last Modified: 12 Apr 2025

    IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary text files via a crafted XML/XSLT function in a SELECT statement.

    Published: 20 Jul 2015
    3.5
    Low

    CVE-2015-0130

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Quality Manager (RQM) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Team Concert (RTC) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5; Rational Requirements Composer (RRC) 4.x through 4.0.7; and Rational DOORS Next Generation (RDNG) 4.x before 4.0.7 IF6 and 5.x before 5.0.2 IF5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 20 Jul 2015
    4
    Medium

    CVE-2015-1984

    Last Modified: 12 Apr 2025

    IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified vectors, as demonstrated by discovering usernames for use in brute-force attacks.

    Published: 20 Jul 2015
    7.6
    High

    CVE-2014-9196

    Last Modified: 5 Sept 2025

    Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

    Published: 20 Jul 2015
    6.8
    Medium

    CVE-2015-0157

    Last Modified: 12 Apr 2025

    IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by leveraging an unspecified scalar function in a SQL statement.

    Published: 20 Jul 2015
    4
    Medium

    CVE-2015-1883

    Last Modified: 12 Apr 2025

    IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read certain administrative files via crafted use of an automated-maintenance policy stored procedure.

    Published: 20 Jul 2015
    8
    High

    CVE-2015-1935

    Last Modified: 12 Apr 2025

    The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors.

    Published: 20 Jul 2015
    3.5
    Low

    CVE-2015-1968

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 20 Jul 2015
    3.5
    Low

    CVE-2015-1979

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Error dialog in IBM Case Manager 5.2.1 before 5.2.1.2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input to the (1) addressability or (2) comments component.

    Published: 20 Jul 2015
    3.5
    Low

    CVE-2015-1980

    Last Modified: 12 Apr 2025

    IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.

    Published: 20 Jul 2015
    6.8
    Medium

    CVE-2015-4111

    Last Modified: 12 Apr 2025

    mc_demux_mp4_ds.ax in an unspecified third-party codec demux in BlackBerry Link before 1.2.3.53 with installer before 1.1.0.22 allows remote attackers to execute arbitrary code via a crafted MP4 file.

    Published: 20 Jul 2015
    7.5
    High

    CVE-2014-10077

    Last Modified: 21 Nov 2024

    Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.

    Published: 20 Jul 2015
    5.5
    Medium

    CVE-2015-1931

    Last Modified: 21 Nov 2024

    IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.

    Published: 20 Jul 2015
    7.5
    High

    CVE-2015-2972

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Sysphonic Thetis before 2.3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Jul 2015
    5.5
    Medium

    CVE-2015-2971

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string.

    Published: 19 Jul 2015
    5
    Medium

    CVE-2015-4280

    Last Modified: 12 Apr 2025

    Cisco Prime Collaboration Assurance 10.0 allows remote attackers to cause a denial of service (HTTP service outage) via a crafted HTTP request, aka Bug ID CSCum38844.

    Published: 18 Jul 2015
    7.8
    High

    CVE-2015-5374

    Last Modified: 12 Apr 2025

    A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02. Specially crafted packets sent to port 50000/UDP could cause a denial-of-service of the affected device. A manual reboot may be required to recover the service of the device.

    Published: 18 Jul 2015