CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2015-2414

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to obtain sensitive browsing-history information via vectors related to image caching, aka "Internet Explorer Information Disclosure Vulnerability."

    Published: 14 Jul 2015
    7.2
    High

    CVE-2015-3007

    Last Modified: 12 Apr 2025

    The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set system ports console insecure" feature, which allows physically proximate attackers to gain administrative privileges by leveraging access to the console port.

    Published: 14 Jul 2015
    7.1
    High

    CVE-2015-5358

    Last Modified: 12 Apr 2025

    Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D35, 13.2X52 before 13.2X52-D25, 13.3 before 13.3R6, 14.1R3 before 14.1R3-S2, 14.1 before 14.1R4, 14.1X53 before 14.1X53-D12, 14.1X53 before 14.1X53-D16, 14.1X55 before 14.1X55-D25, 14.2 before 14.2R2, and 15.1 before 15.1R1 allows remote attackers to cause a denial of service (mbuf and connection consumption and restart) via a large number of requests that trigger a TCP connection to move to the LAST_ACK state when there is more data to send.

    Published: 14 Jul 2015
    4.3
    Medium

    CVE-2015-4270

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT System Software 5.3.1.5 and 6.0.0 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuv22557, CSCuv22583, CSCuv22632, CSCuv22641, CSCuv22650, CSCuv22662, CSCuv22697, and CSCuv22702.

    Published: 14 Jul 2015
    7.1
    High

    CVE-2015-5359

    Last Modified: 12 Apr 2025

    Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D10, 13.2 before 13.2R7, 13.3 before 13.3R5, 14.1R3 before 14.1R3-S2, 14.1 before 14.1R4, 14.2 before 14.2R2, and 15.1 before 15.1R1 allows remote attackers to cause a denial of service (NULL pointer dereference and RDP crash) via a large number of BGP-VPLS advertisements with updated BGP local preference values.

    Published: 14 Jul 2015
    9.3
    Critical

    CVE-2015-5362

    Last Modified: 12 Apr 2025

    The BFD daemon in Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R8, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.1X50 before 14.1X50-D85, 14.1X55 before 14.1X55-D20, 14.2 before 14.2R3, 15.1 before 15.1R1, and 15.1X49 before 15.1X49-D10 allows remote attackers to cause a denial of service (bfdd crash and restart) or execute arbitrary code via a crafted BFD packet.

    Published: 14 Jul 2015
    6
    Medium

    CVE-2015-1936

    Last Modified: 12 Apr 2025

    The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.

    Published: 14 Jul 2015
    6.8
    Medium

    CVE-2015-1927

    Last Modified: 12 Apr 2025

    The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webcontainer.disallowServeServletsByClassname WebContainer property, which allows remote attackers to obtain privileged access via unspecified vectors.

    Published: 14 Jul 2015
    4.4
    Medium

    CVE-2015-1946

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unspecified vectors.

    Published: 14 Jul 2015
    4.3
    Medium

    CVE-2015-4268

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1.2(1.198) and 1.3(0.876) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCus16052.

    Published: 14 Jul 2015
    7.5
    High

    CVE-2015-5147

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the header_anchor function in the HTML renderer in Redcarpet before 3.3.2 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

    Published: 14 Jul 2015
    6.8
    Medium

    CVE-2015-5397

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.2 allows remote attackers to hijack the authentication of unspecified victims for requests that upload code via unknown vectors.

    Published: 14 Jul 2015
    4.3
    Medium

    CVE-2015-5519

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the applyConvolution demo in WideImage 11.02.19 allows remote attackers to inject arbitrary web script or HTML via the matrix parameter to demo/index.php.

    Published: 14 Jul 2015
    4.3
    Medium

    CVE-2015-5520

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the username when creating a new user account, which is not properly handled when deleting an account.

    Published: 14 Jul 2015
    4.8
    Medium

    CVE-2015-5521

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in BlackCat CMS 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the name in a new group to backend/groups/index.php.

    Published: 14 Jul 2015
    7.5
    High

    CVE-2015-1560

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon web 2.7.0) allows remote attackers to execute arbitrary SQL commands via the sid parameter to include/common/XmlTree/GetXmlTree.php.

    Published: 14 Jul 2015
    6.5
    Medium

    CVE-2015-1561

    Last Modified: 12 Apr 2025

    The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter.

    Published: 14 Jul 2015
    4
    Medium

    CVE-2015-4269

    Last Modified: 12 Apr 2025

    The Tomcat throttling feature in Cisco Unified Communications Manager 10.5(1.99995.9) allows remote authenticated users to cause a denial of service (management outage) by sending many requests, aka Bug ID CSCuu99709.

    Published: 14 Jul 2015
    5
    Medium

    CVE-2015-1887

    Last Modified: 12 Apr 2025

    IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a crafted request.

    Published: 14 Jul 2015
    4.3
    Medium

    CVE-2015-1917

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 14 Jul 2015
    3.5
    Low

    CVE-2015-1944

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF17 and 8.5.0 before CF06 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 14 Jul 2015
    4.3
    Medium

    CVE-2015-4272

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the ccmivr page in Cisco Unified Communications Manager (formerly CallManager) 10.5(2.10000.5) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCut19580.

    Published: 14 Jul 2015
    9.8
    Critical

    CVE-2015-2590

    Last Modified: 21 Apr 2026

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

    Published: 14 Jul 2015
    4
    Medium

    CVE-2015-2582

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to GIS.

    Published: 14 Jul 2015
    5
    Medium

    CVE-2015-2601

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, JRockit R28.3.6, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JCE.

    Published: 14 Jul 2015
    4
    Medium

    CVE-2015-2611

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to DML.

    Published: 14 Jul 2015
    6.5
    Medium

    CVE-2015-2617

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Partition.

    Published: 14 Jul 2015
    4.3
    Medium

    CVE-2015-2620

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges.

    Published: 14 Jul 2015
    10
    Critical

    CVE-2015-2628

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.

    Published: 14 Jul 2015
    5
    Medium

    CVE-2015-2632

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45 allows remote attackers to affect confidentiality via unknown vectors related to 2D.

    Published: 14 Jul 2015
    4.9
    Medium

    CVE-2015-3244

    Last Modified: 12 Apr 2025

    The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted resources, which allows remote attackers to obtain sensitive information via a URL with a modified resource ID.

    Published: 14 Jul 2015
    10
    Critical

    CVE-2015-4733

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.

    Published: 14 Jul 2015
    3.5
    Low

    CVE-2015-4737

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Pluggable Auth.

    Published: 14 Jul 2015
    7.6
    High

    CVE-2015-4748

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.

    Published: 14 Jul 2015
    4.3
    Medium

    CVE-2015-4749

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect availability via vectors related to JNDI.

    Published: 14 Jul 2015
    4
    Medium

    CVE-2015-4756

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-0439.

    Published: 14 Jul 2015
    3.5
    Low

    CVE-2015-4771

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to RBR.

    Published: 14 Jul 2015
    5
    Medium

    CVE-2015-2613

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JCE.

    Published: 14 Jul 2015
    3.5
    Low

    CVE-2015-2639

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Firewall.

    Published: 14 Jul 2015
    4
    Medium

    CVE-2015-2643

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.

    Published: 14 Jul 2015
    4
    Medium

    CVE-2015-2648

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to DML.

    Published: 14 Jul 2015
    2.1
    Low

    CVE-2015-2661

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows local users to affect availability via unknown vectors related to Client.

    Published: 14 Jul 2015
    10
    Critical

    CVE-2015-4731

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; Java SE Embedded 7u75; and Java SE Embedded 8u33 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

    Published: 14 Jul 2015
    10
    Critical

    CVE-2015-4732

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-2590.

    Published: 14 Jul 2015
    4
    Medium

    CVE-2015-4752

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect availability via vectors related to Server : I_S.

    Published: 14 Jul 2015
    3.5
    Low

    CVE-2015-4757

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier and 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.

    Published: 14 Jul 2015
    4
    Medium

    CVE-2015-4772

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition.

    Published: 14 Jul 2015
    4.3
    Medium

    CVE-2015-2596

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u80 allows remote attackers to affect integrity via unknown vectors related to Hotspot.

    Published: 14 Jul 2015
    7.2
    High

    CVE-2015-2597

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u80 and 8u45 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Install.

    Published: 14 Jul 2015
    5
    Medium

    CVE-2015-2619

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, JavaFX 2.2.80, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via unknown vectors related to 2D.

    Published: 14 Jul 2015