CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2015-3239

    Last Modified: 12 Apr 2025

    Off-by-one error in the dwarf_to_unw_regnum function in include/dwarf_i.h in libunwind 1.1 allows local users to have unspecified impact via invalid dwarf opcodes.

    Published: 20 Jun 2015
    Unknown

    CVE-2015-2865

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-4640, CVE-2015-4641. Reason: this ID was intended for one issue, but was associated with two issues. Notes: All CVE users should consult CVE-2015-4640 and CVE-2015-4641 to identify the ID or IDs of interest. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 19 Jun 2015
    7.5
    High

    CVE-2015-4678

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Persian Car CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to the default URI.

    Published: 19 Jun 2015
    10
    Critical

    CVE-2015-2797

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the redirect parameter to cgi-bin/login.

    Published: 19 Jun 2015
    2.9
    Low

    CVE-2015-4640

    Last Modified: 12 Apr 2025

    The SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices relies on an HTTP connection to the skslm.swiftkey.net server, which allows man-in-the-middle attackers to write to language-pack files by modifying an HTTP response. NOTE: CVE-2015-4640 exploitation can be combined with CVE-2015-4641 exploitation for man-in-the-middle code execution.

    Published: 19 Jun 2015
    6.4
    Medium

    CVE-2015-4641

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices allows remote web servers to write to arbitrary files, and consequently execute arbitrary code in a privileged context, by leveraging control of the skslm.swiftkey.net domain name and providing a .. (dot dot) in an entry in a ZIP archive, as demonstrated by a traversal to the /data/dalvik-cache directory.

    Published: 19 Jun 2015
    7.5
    High

    CVE-2015-4675

    Last Modified: 12 Apr 2025

    Buffer overflow in the Tiny SRP library (aka TinySRP) allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted size value for the username field.

    Published: 19 Jun 2015
    6.5
    Medium

    CVE-2015-4676

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in ticket.php in TickFa 1.x allows remote authenticated users to execute arbitrary SQL commands via the tid parameter in a read action.

    Published: 19 Jun 2015
    6.8
    Medium

    CVE-2015-4677

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in FiverrScript (aka Fiverr Script) 7.2 allows remote attackers to hijack the authentication of administrators for requests that create a new admin via a request to administrator/admins_create.php.

    Published: 19 Jun 2015
    4.3
    Medium

    CVE-2015-4679

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Airties RT-210 allow remote attackers to inject arbitrary web script or HTML via the (1) ddns_domainame or (2) ddns_account parameter to ddns.stm.

    Published: 19 Jun 2015
    5
    Medium

    CVE-2015-4194

    Last Modified: 12 Apr 2025

    The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login attempts depending on whether the username exists or corresponds to a privileged account, which allows remote attackers to enumerate account names and obtain sensitive information via a series of requests, aka Bug ID CSCuf28861.

    Published: 19 Jun 2015
    4
    Medium

    CVE-2015-4195

    Last Modified: 12 Apr 2025

    Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, and SSH and TELNET outage) via a crafted disconnect action within an SSH session, aka Bug ID CSCul63127.

    Published: 19 Jun 2015
    5
    Medium

    CVE-2015-4191

    Last Modified: 12 Apr 2025

    Cisco IOS XR 5.2.1 allows remote attackers to cause a denial of service (ipv6_io service reload) via a malformed IPv6 packet, aka Bug ID CSCuq95565.

    Published: 19 Jun 2015
    4.3
    Medium

    CVE-2015-3908

    Last Modified: 12 Apr 2025

    Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 19 Jun 2015
    7.8
    High

    CVE-2015-6240

    Last Modified: 20 Apr 2025

    The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.

    Published: 19 Jun 2015
    5
    Medium

    CVE-2015-3897

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the location parameter to bonita/portal/themeResource.

    Published: 18 Jun 2015
    4.3
    Medium

    CVE-2015-4655

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Synology DiskStation Manager (DSM) before 5.2-5565 Update 1 allows remote attackers to inject arbitrary web script or HTML via the "compound" parameter to entry.cgi.

    Published: 18 Jun 2015
    6.8
    Medium

    CVE-2015-4659

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php.

    Published: 18 Jun 2015
    4.3
    Medium

    CVE-2015-3422

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in SearchBlox before 8.2.1 allows remote attackers to inject arbitrary web script or HTML via the menu2 parameter to admin/main.jsp.

    Published: 18 Jun 2015
    3.5
    Low

    CVE-2015-4139

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in smilies4wp.php in the WP Smiley plugin 1.4.1 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the s4w-more parameter to wp-admin/options-general.php.

    Published: 18 Jun 2015
    4.3
    Medium

    CVE-2015-4587

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote attackers to inject arbitrary web script or HTML via the "Custom application" field in the "port triggering" menu.

    Published: 18 Jun 2015
    6.8
    Medium

    CVE-2015-4140

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the WP Smiley plugin 1.4.1 for WordPress allows remote attackers to hijack the authentication of editors for requests that conduct cross-site scripting (XSS) attacks via the s4w-more parameter to the smilies4wp.php page to wp-admin/options-general.php.

    Published: 18 Jun 2015
    4.3
    Medium

    CVE-2015-4420

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) crafted check plugin, the (2) description in a host profile, or the (3) plugin_args parameter to a Test service check page.

    Published: 18 Jun 2015
    4.3
    Medium

    CVE-2015-4661

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Symphony CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the sort parameter to system/authors.

    Published: 18 Jun 2015
    4.3
    Medium

    CVE-2015-4660

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Enhanced SQL Portal 5.0.7961 allows remote attackers to inject arbitrary web script or HTML via the id parameter to iframe.php.

    Published: 18 Jun 2015
    7.5
    High

    CVE-2015-4654

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the EQ Event Calendar component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to eqfullevent.

    Published: 18 Jun 2015
    4.3
    Medium

    CVE-2015-4656

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station before 6.3-2945 allow remote attackers to inject arbitrary web script or HTML via the (1) success parameter to login.php or (2) crafted URL parameters to index.php, as demonstrated by the t parameter to photo/.

    Published: 18 Jun 2015
    4.3
    Medium

    CVE-2015-4657

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Mailbird 2.0.16.0 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with a crafted URL.

    Published: 18 Jun 2015
    7.5
    High

    CVE-2015-4658

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) usr or (2) pwd parameter.

    Published: 18 Jun 2015
    6.8
    Medium

    CVE-2015-2861

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Vesta Control Panel before 0.9.8-14 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 18 Jun 2015
    6.5
    Medium

    CVE-2015-4628

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands via the sid parameter.

    Published: 18 Jun 2015
    7.5
    High

    CVE-2015-8076

    Last Modified: 12 Apr 2025

    The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain sensitive information or possibly have unspecified other impact via vectors related to the urlfetch range, which triggers an out-of-bounds heap read.

    Published: 18 Jun 2015
    5.5
    Medium

    CVE-2015-3243

    Last Modified: 20 Apr 2025

    rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.

    Published: 18 Jun 2015
    6
    Medium

    CVE-2015-2803

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3 allows remote authenticated users with permission to maintain acronyms to execute arbitrary SQL commands via the id parameter.

    Published: 17 Jun 2015
    7.5
    High

    CVE-2015-4454

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.

    Published: 17 Jun 2015
    4.3
    Medium

    CVE-2012-6692

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in js/wp-seo-metabox.js in the WordPress SEO by Yoast plugin before 2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_title parameter to wp-admin/post-new.php, which is not properly handled in the snippet preview functionality.

    Published: 17 Jun 2015
    4.3
    Medium

    CVE-2015-2665

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Jun 2015
    4.3
    Medium

    CVE-2015-3429

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.

    Published: 17 Jun 2015
    6.5
    Medium

    CVE-2015-4336

    Last Modified: 12 Apr 2025

    cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file.

    Published: 17 Jun 2015
    3.5
    Low

    CVE-2015-4337

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the excl_manual parameter in the xcloner_show page to wpadmin/plugins.php.

    Published: 17 Jun 2015
    6.5
    Medium

    CVE-2015-4338

    Last Modified: 12 Apr 2025

    Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the language files via a Translation LM_FRONT_* field for a language, as demonstrated by language/italian.php.

    Published: 17 Jun 2015
    7.5
    High

    CVE-2015-4342

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id.

    Published: 17 Jun 2015
    5
    Medium

    CVE-2015-4414

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player) plugin 1.1.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 17 Jun 2015
    4.3
    Medium

    CVE-2015-4550

    Last Modified: 12 Apr 2025

    The Cavium cryptographic-module firmware on Cisco Adaptive Security Appliance (ASA) devices with software 9.3(3) and 9.4(1.1) does not verify the AES-GCM Integrity Check Value (ICV) octets, which makes it easier for man-in-the-middle attackers to spoof IPSec and IKEv2 traffic by modifying packet data, aka Bug ID CSCuu66218.

    Published: 17 Jun 2015
    4.6
    Medium

    CVE-2015-3316

    Last Modified: 12 Apr 2025

    CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, allows local users to gain privileges via an unspecified environment variable.

    Published: 17 Jun 2015
    4.6
    Medium

    CVE-2015-3317

    Last Modified: 12 Apr 2025

    CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, does not properly perform bounds checking, which allows local users to gain privileges via unspecified vectors.

    Published: 17 Jun 2015
    4.6
    Medium

    CVE-2015-3318

    Last Modified: 12 Apr 2025

    CA Common Services, as used in CA Client Automation r12.5 SP01, r12.8, and r12.9; CA Network and Systems Management r11.0, r11.1, and r11.2; CA NSM Job Management Option r11.0, r11.1, and r11.2; CA Universal Job Management Agent; CA Virtual Assurance for Infrastructure Managers (aka SystemEDGE) 12.6, 12.7, 12.8, and 12.9; and CA Workload Automation AE r11, r11.3, r11.3.5, and r11.3.6 on UNIX, does not properly validate an unspecified variable, which allows local users to gain privileges via unknown vectors.

    Published: 17 Jun 2015
    7.2
    High

    CVE-2015-4183

    Last Modified: 12 Apr 2025

    Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI parameter, aka Bug ID CSCut32795.

    Published: 17 Jun 2015
    7.2
    High

    CVE-2015-4186

    Last Modified: 12 Apr 2025

    The diagnostics subsystem in the administrative web interface on Cisco Virtualization Experience (aka VXC) Client 6215 devices with firmware 11.2(27.4) allows local users to gain privileges for OS command execution via a crafted option value, aka Bug ID CSCug54412.

    Published: 17 Jun 2015
    10
    Critical

    CVE-2015-0546

    Last Modified: 12 Apr 2025

    EMC Unified Infrastructure Manager/Provisioning (UIM/P) 4.1 allows remote attackers to bypass LDAP authentication by providing a valid account name.

    Published: 17 Jun 2015