CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2015-2621

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33, allows remote attackers to affect confidentiality via vectors related to JMX.

    Published: 14 Jul 2015
    2.6
    Low

    CVE-2015-2627

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45 allows remote attackers to affect confidentiality via unknown vectors related to installation.

    Published: 14 Jul 2015
    5
    Medium

    CVE-2015-2637

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JavaFX 2.2.80; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via unknown vectors related to 2D.

    Published: 14 Jul 2015
    10
    Critical

    CVE-2015-2638

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JavaFX 2.2.80; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

    Published: 14 Jul 2015
    3.5
    Low

    CVE-2015-2641

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Privileges.

    Published: 14 Jul 2015
    5
    Medium

    CVE-2015-2659

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8u45 and Java SE Embedded 8u33 allows remote attackers to affect availability via unknown vectors related to Security.

    Published: 14 Jul 2015
    6.9
    Medium

    CVE-2015-2664

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

    Published: 14 Jul 2015
    4
    Medium

    CVE-2015-4729

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u80 and 8u45 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Deployment.

    Published: 14 Jul 2015
    9.3
    Critical

    CVE-2015-4736

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u80 and 8u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

    Published: 14 Jul 2015
    10
    Critical

    CVE-2015-4760

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

    Published: 14 Jul 2015
    3.5
    Low

    CVE-2015-4761

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Memcached.

    Published: 14 Jul 2015
    1.7
    Low

    CVE-2015-4767

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Firewall, a different vulnerability than CVE-2015-4769.

    Published: 14 Jul 2015
    3.5
    Low

    CVE-2015-4769

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Firewall, a different vulnerability than CVE-2015-4767.

    Published: 14 Jul 2015
    Unknown

    CVE-2015-8176

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-8176. Reason: This candidate is a duplicate of CVE-2014-8176. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2014-8176 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Jul 2015
    9
    Critical

    CVE-2015-1961

    Last Modified: 12 Apr 2025

    The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions and execute arbitrary JavaScript code on the server via an unspecified API call.

    Published: 13 Jul 2015
    Unknown

    CVE-2015-4249

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue in customer-controlled software. Notes: none

    Published: 13 Jul 2015
    7.5
    High

    CVE-2015-8877

    Last Modified: 12 Apr 2025

    The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uses inconsistent allocate and free approaches, which allows remote attackers to cause a denial of service (memory consumption) via a crafted call, as demonstrated by a call to the PHP imagescale function.

    Published: 13 Jul 2015
    4.3
    Medium

    CVE-2015-4236

    Last Modified: 12 Apr 2025

    Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13704 and CSCuq05636.

    Published: 10 Jul 2015
    4
    Medium

    CVE-2015-4263

    Last Modified: 12 Apr 2025

    The Control and Provisioning functionality in Cisco Mobility Services Engine (MSE) 10.0(0.1) allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCut36851.

    Published: 10 Jul 2015
    7.2
    High

    CVE-2015-4526

    Last Modified: 12 Apr 2025

    EMC RecoverPoint for Virtual Machines (VMs) 4.2 allows local users to obtain root-shell access by bypassing the Installation Manager Boxmgmt CLI interface.

    Published: 10 Jul 2015
    4.3
    Medium

    CVE-2015-2963

    Last Modified: 12 Apr 2025

    The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg.

    Published: 10 Jul 2015
    7.2
    High

    CVE-2015-3650

    Last Modified: 12 Apr 2025

    vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer during the setup of the vprintproxy.exe process, which allows host OS users to gain host OS privileges by injecting a thread.

    Published: 10 Jul 2015
    6.8
    Medium

    CVE-2015-4254

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence Advanced Media Gateway devices with software 1.1(1.40) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90732.

    Published: 10 Jul 2015
    4.3
    Medium

    CVE-2015-2967

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Jul 2015
    4.3
    Medium

    CVE-2015-2969

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in LEMON-S PHP Simple Oekaki BBS before 1.21 allows remote attackers to inject arbitrary web script or HTML via the oekakis parameter.

    Published: 10 Jul 2015
    6.4
    Medium

    CVE-2015-2970

    Last Modified: 12 Apr 2025

    index.php in LEMON-S PHP Simple Oekaki BBS before 1.21 allows remote attackers to delete arbitrary files via the oekakis parameter.

    Published: 10 Jul 2015
    4.3
    Medium

    CVE-2015-4259

    Last Modified: 12 Apr 2025

    The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by leveraging knowledge of a private key, aka Bug IDs CSCum56133 and CSCum56177.

    Published: 10 Jul 2015
    4.3
    Medium

    CVE-2015-4260

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Hosted Collaboration Solution 10.6(1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu14862.

    Published: 10 Jul 2015
    7.2
    High

    CVE-2015-4244

    Last Modified: 12 Apr 2025

    The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.

    Published: 10 Jul 2015
    9.8
    Critical

    CVE-2015-5123

    Last Modified: 21 Apr 2026

    Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

    Published: 10 Jul 2015
    9.8
    Critical

    CVE-2015-5122

    Last Modified: 21 Apr 2026

    Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

    Published: 10 Jul 2015
    4.3
    Medium

    CVE-2015-8075

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 10 Jul 2015
    6.8
    Medium

    CVE-2015-4258

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MSE 8000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90444.

    Published: 10 Jul 2015
    6.8
    Medium

    CVE-2015-4252

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence ISDN Gateway devices with software 2.2(1.106) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90724.

    Published: 10 Jul 2015
    6.8
    Medium

    CVE-2015-4253

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence Serial Gateway devices with software 1.0(1.42) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90728.

    Published: 10 Jul 2015
    6.8
    Medium

    CVE-2015-4255

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP Gateway devices with software 2.0(3.34) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90734.

    Published: 10 Jul 2015
    6.8
    Medium

    CVE-2015-4256

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP VCR devices with software 3.0(1.27) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90736.

    Published: 10 Jul 2015
    6.8
    Medium

    CVE-2015-4257

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MCU 4500 devices with software 4.5(1.55) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90710.

    Published: 10 Jul 2015
    4.3
    Medium

    CVE-2015-3267

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the 404 error page in Red Hat JBoss Operations Network before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 9 Jul 2015
    6.5
    Medium

    CVE-2015-3254

    Last Modified: 20 Apr 2025

    The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.

    Published: 9 Jul 2015
    6.5
    Medium

    CVE-2015-1793

    Last Modified: 12 Apr 2025

    The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.

    Published: 9 Jul 2015
    5
    Medium

    CVE-2015-4616

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allows remote attackers to create arbitrary files via a .. (dot dot) in the map_id parameter.

    Published: 8 Jul 2015
    4.3
    Medium

    CVE-2015-5460

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in app/views/events/_menu.html.erb in Snorby 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the title (cls.name variable) when creating a classification.

    Published: 8 Jul 2015
    6.4
    Medium

    CVE-2015-5461

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Redirect function in stageshow_redirect.php in the StageShow plugin before 5.0.9 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

    Published: 8 Jul 2015
    7.5
    High

    CVE-2015-4614

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the mapName parameter in an e2m_img_save_map_name action to wp-admin/admin-ajax.php and other unspecified vectors.

    Published: 8 Jul 2015
    4.3
    Medium

    CVE-2015-5454

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Nucleus CMS allows remote attackers to inject arbitrary web script or HTML via the title parameter when adding a new item.

    Published: 8 Jul 2015
    4.3
    Medium

    CVE-2015-5455

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in X-Cart 4.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to install/.

    Published: 8 Jul 2015
    4.3
    Medium

    CVE-2015-5456

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the form method in modules/formclass.php in PivotX before 2.3.11 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, related to the "PHP_SELF" variable and form actions.

    Published: 8 Jul 2015
    4.3
    Medium

    CVE-2014-9741

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Desktop, ArcGIS for Engine, and ArcGIS for Server 10.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Jul 2015
    7.5
    High

    CVE-2015-5452

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid cookie, as demonstrated by a request to borderpost/imp/compose.php3.

    Published: 8 Jul 2015