CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2015-2850

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in index-login.ant in the ANTlabs InnGate firmware on IG 3100, InnGate 3.01 E, InnGate 3.10 E, InnGate 3.10 M, SG 4, and SSG 4 devices allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 7 Jul 2015
    9.8
    Critical

    CVE-2015-5119

    Last Modified: 21 Apr 2026

    Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

    Published: 7 Jul 2015
    6.8
    Medium

    CVE-2015-3259

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long configuration argument.

    Published: 7 Jul 2015
    7.8
    High

    CVE-2015-4620

    Last Modified: 12 Apr 2025

    name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNSSEC validation, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) by constructing crafted zone data and then making a query for a name in that zone.

    Published: 7 Jul 2015
    7.6
    High

    CVE-2014-5406

    Last Modified: 3 Nov 2025

    The Hospira LifeCare PCA Infusion System before 7.0 does not validate network traffic associated with sending a (1) drug library, (2) software update, or (3) configuration change, which allows remote attackers to modify settings or medication data via packets on the (a) TELNET, (b) HTTP, (c) HTTPS, or (d) UPNP port. NOTE: this issue might overlap CVE-2015-3459.

    Published: 6 Jul 2015
    10
    Critical

    CVE-2015-3955

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 6 Jul 2015
    5
    Medium

    CVE-2015-1011

    Last Modified: 12 Apr 2025

    Hospira LifeCare PCA Infusion System before 7.0 has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

    Published: 6 Jul 2015
    4.6
    Medium

    CVE-2015-3957

    Last Modified: 12 Apr 2025

    Hospira LifeCare PCA Infusion System before 7.0 stores private keys and certificates, which has unspecified impact and attack vectors.

    Published: 6 Jul 2015
    7.8
    High

    CVE-2015-3958

    Last Modified: 12 Apr 2025

    Hospira LifeCare PCA Infusion System 5.0 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (forced manual reboot) via a flood of TCP packets.

    Published: 6 Jul 2015
    2.1
    Low

    CVE-2014-9740

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Rules Link module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer rules links" permission to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in the (1) question and (2) description strings in a confirmation form for a triggering Rules link.

    Published: 6 Jul 2015
    5
    Medium

    CVE-2015-3281

    Last Modified: 12 Apr 2025

    The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.

    Published: 6 Jul 2015
    5.8
    Medium

    CVE-2014-9737

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Language Switcher Dropdown module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a block.

    Published: 6 Jul 2015
    4.3
    Medium

    CVE-2014-9738

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title.

    Published: 6 Jul 2015
    3.5
    Low

    CVE-2014-9739

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Node Field module 7.x-2.x before 7.x-2.45 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors involving internal fields.

    Published: 6 Jul 2015
    7.8
    High

    CVE-2015-4230

    Last Modified: 12 Apr 2025

    Memory leak in Cisco Headend System Release allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, aka Bug ID CSCus91854.

    Published: 6 Jul 2015
    10
    Critical

    CVE-2015-5371

    Last Modified: 12 Apr 2025

    The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scripts via unspecified vectors.

    Published: 6 Jul 2015
    7.2
    High

    CVE-2015-2126

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in pppoec in HP HP-UX 11iv2 and 11iv3 allows local users to gain privileges by leveraging setuid permissions.

    Published: 6 Jul 2015
    7.9
    High

    CVE-2015-4034

    Last Modified: 12 Apr 2025

    The createFromParcel method in the com.absolute.android.persistence.MethodSpec class in Samsung Galaxy S5s allows remote attackers to execute arbitrary files via a crafted Parcelable object in a serialized MethodSpec object.

    Published: 6 Jul 2015
    3.3
    Low

    CVE-2015-4033

    Last Modified: 12 Apr 2025

    Samsung SBeam allows remote attackers to read arbitrary images by leveraging an NFC connection to access the HTTP server on port 15000.

    Published: 6 Jul 2015
    6.8
    Medium

    CVE-2015-4647

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in Ipropsapi in Panasonic Security API (PS-API) ActiveX SDK before 8.10.18 allow remote attackers to execute arbitrary code via a long string in the (1) FilePassword property or to the (2) GetStringInfo method.

    Published: 6 Jul 2015
    7.5
    High

    CVE-2015-4648

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the Ipropsapi.ipropsapiCtrl.1 ActiveX control in ipropsapivideo in Panasonic Security API (PS-API) ActiveX SDK before 8.10.18 allows remote attackers to execute arbitrary code via a long string to the MulticastAddr method.

    Published: 6 Jul 2015
    4.3
    Medium

    CVE-2015-2742

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.

    Published: 6 Jul 2015
    6.8
    Medium

    CVE-2015-5400

    Last Modified: 12 Apr 2025

    Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.

    Published: 6 Jul 2015
    7.8
    High

    CVE-2015-3288

    Last Modified: 12 Apr 2025

    mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (page tainting) via a crafted application that triggers writing to page zero.

    Published: 6 Jul 2015
    5.9
    Medium

    CVE-2015-8878

    Last Modified: 12 Apr 2025

    main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race condition and heap memory corruption) by leveraging an application that performs many temporary-file accesses.

    Published: 6 Jul 2015
    5.8
    Medium

    CVE-2015-0543

    Last Modified: 12 Apr 2025

    EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 5 Jul 2015
    9.3
    Critical

    CVE-2015-0544

    Last Modified: 12 Apr 2025

    EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value.

    Published: 5 Jul 2015
    6.5
    Medium

    CVE-2015-4129

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Subrion CMS before 3.3.3 allows remote authenticated users to execute arbitrary SQL commands via modified serialized data in a salt cookie.

    Published: 5 Jul 2015
    5
    Medium

    CVE-2015-2964

    Last Modified: 12 Apr 2025

    NAMSHI | JOSE 5.0.0 and earlier allows remote attackers to bypass signature verification via crafted tokens in a JSON Web Tokens (JWT) header.

    Published: 5 Jul 2015
    5
    Medium

    CVE-2015-4453

    Last Modified: 12 Apr 2025

    interface/globals.php in OpenEMR 2.x, 3.x, and 4.x before 4.2.0 patch 2 allows remote attackers to bypass authentication and obtain sensitive information via an ignoreAuth=1 value to certain scripts, as demonstrated by (1) interface/fax/fax_dispatch_newpid.php and (2) interface/billing/sl_eob_search.php.

    Published: 5 Jul 2015
    7.3
    High

    CVE-2015-5590

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the phar_fix_filepath function in ext/phar/phar.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large length value, as demonstrated by mishandling of an e-mail attachment by the imap PHP extension.

    Published: 5 Jul 2015
    9.8
    Critical

    CVE-2015-5589

    Last Modified: 12 Apr 2025

    The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 does not validate a file pointer before a close operation, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted TAR archive that is mishandled in a Phar::convertToData call.

    Published: 5 Jul 2015
    3.5
    Low

    CVE-2015-0551

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5 SP7 before P25; and Documentum Task Space 6.7SP1 before P31 and 6.7SP2 before P23 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Jul 2015
    4.3
    Medium

    CVE-2015-1966

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9, and 6.2.2 before FP15, as used in Security Access Manager for Mobile and other products, allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to the (1) ERROR_DESCRIPTION and (2) TOKEN:RelayState macros.

    Published: 4 Jul 2015
    6.5
    Medium

    CVE-2015-4524

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before P23, and 6.8 before P01; Documentum Administrator 6.7SP1 before P31, 6.7SP2 before P23, 7.0 before P18, 7.1 before P15, and 7.2 before P01; Documentum Digital Assets Manager 6.5SP6 before P25; Documentum Web Publishers 6.5 SP7 before P25; and Documentum Task Space 6.7SP1 before P31 and 6.7SP2 before P23 allows remote authenticated users to execute arbitrary code by uploading a file to the backend Content Server.

    Published: 4 Jul 2015
    4
    Medium

    CVE-2015-0547

    Last Modified: 12 Apr 2025

    The D2CenterstageService.getComments service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.

    Published: 4 Jul 2015
    4
    Medium

    CVE-2015-0548

    Last Modified: 12 Apr 2025

    The D2DownloadService.getDownloadUrls service method in EMC Documentum D2 4.1 and 4.2 before 4.2 P16 and 4.5 before P03 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and bypass intended read-access restrictions via unspecified vectors.

    Published: 4 Jul 2015
    5
    Medium

    CVE-2015-4196

    Last Modified: 12 Apr 2025

    Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain root access by leveraging knowledge of this password and entering it in an SSH session, aka Bug ID CSCuq45546.

    Published: 4 Jul 2015
    9
    Critical

    CVE-2015-4525

    Last Modified: 12 Apr 2025

    The log-gather implementation in the web administration interface in EMC Isilon OneFS 6.5.x.x through 7.1.1.x before 7.1.1.5 and 7.2.0.x before 7.2.0.2 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.

    Published: 4 Jul 2015
    4.6
    Medium

    CVE-2015-4237

    Last Modified: 12 Apr 2025

    The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436.

    Published: 3 Jul 2015
    4.6
    Medium

    CVE-2015-4232

    Last Modified: 12 Apr 2025

    Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID CSCus44856.

    Published: 3 Jul 2015
    3.6
    Low

    CVE-2015-4231

    Last Modified: 12 Apr 2025

    The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-4234

    Last Modified: 12 Apr 2025

    Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.

    Published: 3 Jul 2015
    6.1
    Medium

    CVE-2015-4239

    Last Modified: 12 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software 9.3(2.243) and 100.13(0.21) allows remote attackers to cause a denial of service (device reload) by sending crafted OSPFv2 packets on the local network, aka Bug ID CSCus84220.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3659

    Last Modified: 12 Apr 2025

    The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly restrict access to SQL functions, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3667

    Last Modified: 12 Apr 2025

    QT Media Foundation in Apple QuickTime before 7.7.7, as used in OS X before 10.10.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3661, CVE-2015-3662, CVE-2015-3663, CVE-2015-3666, and CVE-2015-3668.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-3671

    Last Modified: 12 Apr 2025

    Admin Framework in Apple OS X before 10.10.4 does not properly verify XPC entitlements, which allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

    Published: 3 Jul 2015
    7.2
    High

    CVE-2015-3672

    Last Modified: 12 Apr 2025

    Admin Framework in Apple OS X before 10.10.4 does not properly handle authentication errors, which allows local users to obtain admin privileges via unspecified vectors.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3680

    Last Modified: 12 Apr 2025

    Apple Type Services (ATS) in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-3679, CVE-2015-3681, and CVE-2015-3682.

    Published: 3 Jul 2015
    6.8
    Medium

    CVE-2015-3688

    Last Modified: 12 Apr 2025

    CoreText in Apple iOS before 8.4 and OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted text file, a different vulnerability than CVE-2015-3685, CVE-2015-3686, CVE-2015-3687, and CVE-2015-3689.

    Published: 3 Jul 2015