CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2015-4188

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Manager interface in Cisco Prime Collaboration 10.5(1) allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug IDs CSCuu29910, CSCuu29928, and CSCuu59104.

    Published: 17 Jun 2015
    4.3
    Medium

    CVE-2015-4190

    Last Modified: 12 Apr 2025

    Cisco Cloud Portal in Cisco Prime Service Catalog 9.4.1_vortex on Cloud Portal appliances allows man-in-the-middle attackers to modify data via unspecified vectors, aka Bug ID CSCuh19683.

    Published: 17 Jun 2015
    5
    Medium

    CVE-2015-3236

    Last Modified: 12 Apr 2025

    cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 17 Jun 2015
    6.4
    Medium

    CVE-2015-3237

    Last Modified: 12 Apr 2025

    The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.

    Published: 17 Jun 2015
    5
    Medium

    CVE-2015-4651

    Last Modified: 12 Apr 2025

    The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 17 Jun 2015
    4.3
    Medium

    CVE-2015-4652

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-gsm_a_dtap.c in the GSM DTAP dissector in Wireshark 1.12.x before 1.12.6 does not properly validate digit characters, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the de_emerg_num_list and de_bcd_num functions.

    Published: 17 Jun 2015
    5.5
    Medium

    CVE-2015-4645

    Last Modified: 20 Apr 2025

    Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.

    Published: 17 Jun 2015
    7.5
    High

    CVE-2015-4646

    Last Modified: 20 Apr 2025

    (1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.

    Published: 17 Jun 2015
    3.5
    Low

    CVE-2015-4374

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.23, 7.x-3.x before 7.x-3.23, and 7.x-4.x before 7.x-4.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a component name in the recipient (To) address of an email.

    Published: 16 Jun 2015
    5.8
    Medium

    CVE-2015-4398

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors involving processing confirmation delete pages.

    Published: 16 Jun 2015
    4.3
    Medium

    CVE-2015-2804

    Last Modified: 12 Apr 2025

    The management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, and 6855 with firmware before 6.6.4.309.R01 and 6.6.5.x before 6.6.5.80.R02 generates weak session identifiers, which allows remote attackers to hijack arbitrary sessions via a brute force attack.

    Published: 16 Jun 2015
    7.5
    High

    CVE-2015-4607

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the Frontend User Upload (feupload) extension 0.5.0 and earlier for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension using a frontend form, then accessing it via a direct request to the file in the fileadmin folder.

    Published: 16 Jun 2015
    6.8
    Medium

    CVE-2015-2805

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, 10K, and 6860 with firmware 6.4.5.R02, 6.4.6.R01, 6.6.4.R01, 6.6.5.R02, 7.3.2.R01, 7.3.3.R01, 7.3.4.R01, and 8.1.1.R01 allows remote attackers to hijack the authentication of administrators for requests that create users via a crafted request.

    Published: 16 Jun 2015
    3.5
    Low

    CVE-2015-4608

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the BE User Log (beko_beuserlog) extension 1.1.1 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Jun 2015
    7.5
    High

    CVE-2015-3205

    Last Modified: 12 Apr 2025

    libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file, related to "free" function calls in the "lexer's memory clean-up procedure."

    Published: 16 Jun 2015
    6.8
    Medium

    CVE-2015-3395

    Last Modified: 12 Apr 2025

    The msrle_decode_pal4 function in msrledec.c in Libav before 10.7 and 11.x before 11.4 and FFmpeg before 2.0.7, 2.2.x before 2.2.15, 2.4.x before 2.4.8, 2.5.x before 2.5.6, and 2.6.x before 2.6.2 allows remote attackers to have unspecified impact via a crafted image, related to a pixel pointer, which triggers an out-of-bounds array access.

    Published: 16 Jun 2015
    7.5
    High

    CVE-2015-4606

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the Job Fair (jobfair) extension before 1.0.1 for TYPO3, when using Apache with mod_mime, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the extension upload folder.

    Published: 16 Jun 2015
    6.5
    Medium

    CVE-2015-4609

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the wt_directory extension before 1.4.2 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 16 Jun 2015
    6.5
    Medium

    CVE-2015-4610

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Store Locator (locator) extension before 3.3.1 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 16 Jun 2015
    6.5
    Medium

    CVE-2015-4611

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Smoelenboek (ncgov_smoelenboek) extension before 1.0.9 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 16 Jun 2015
    6.5
    Medium

    CVE-2015-4612

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the "FAQ - Frequently Asked Questions" (js_faq) extension before 1.2.1 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 16 Jun 2015
    6.5
    Medium

    CVE-2015-4613

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the backend module in the Developer Log (devlog) extension before 2.11.4 for TYPO3 allows remote editors to execute arbitrary SQL commands via unspecified vectors.

    Published: 16 Jun 2015
    6
    Medium

    CVE-2015-3235

    Last Modified: 12 Apr 2025

    Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.

    Published: 16 Jun 2015
    5
    Medium

    CVE-2015-1840

    Last Modified: 12 Apr 2025

    jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value.

    Published: 16 Jun 2015
    6.9
    Medium

    CVE-2015-3214

    Last Modified: 12 Apr 2025

    The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.

    Published: 16 Jun 2015
    5
    Medium

    CVE-2015-3225

    Last Modified: 12 Apr 2025

    lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

    Published: 16 Jun 2015
    4.3
    Medium

    CVE-2015-3226

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.

    Published: 16 Jun 2015
    5
    Medium

    CVE-2015-3227

    Last Modified: 12 Apr 2025

    The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.

    Published: 16 Jun 2015
    4.3
    Medium

    CVE-2015-4559

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the product deployment feature in the Java core web services in Intel McAfee ePolicy Orchestrator (ePO) before 5.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Jun 2015
    6.8
    Medium

    CVE-2015-4119

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) administrators for requests that create an administrator account via a request to admin/users_edit.php or (2) arbitrary users for requests that conduct SQL injection attacks via the server parameter to monitor/show_sys_state.php.

    Published: 15 Jun 2015
    6.5
    Medium

    CVE-2015-4118

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote attackers using CVE-2015-4119.2.

    Published: 15 Jun 2015
    6.4
    Medium

    CVE-2015-4152

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attackers to write to arbitrary files via vectors related to dynamic field references in the path option.

    Published: 15 Jun 2015
    6
    Medium

    CVE-2015-4348

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Spider Contacts module for Drupal allows remote authenticated users with the "access Spider Contacts category administration" permission to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jun 2015
    3.5
    Low

    CVE-2015-4356

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the view-based webform results table in the Webform module 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a webform.

    Published: 15 Jun 2015
    3.5
    Low

    CVE-2015-4372

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Image Title module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Jun 2015
    3.5
    Low

    CVE-2015-4380

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Linear Case module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Jun 2015
    5.1
    Medium

    CVE-2015-4396

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Keyword Research module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to hijack the authentication of users with the "kwresearch admin site keywords" permission for requests that (1) create, (2) delete, or (3) set priorities to keywords via unspecified vectors.

    Published: 15 Jun 2015
    5.8
    Medium

    CVE-2015-4349

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Spider Contacts module for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete contact categories via unspecified vectors.

    Published: 15 Jun 2015
    3.5
    Low

    CVE-2015-4357

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.22, 7.x-3.x before 7.x-3.22, and 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title, which is used as the default title of a webform block.

    Published: 15 Jun 2015
    6.8
    Medium

    CVE-2015-4364

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in includes/campaignmonitor_lists.admin.inc in the Campaign Monitor module 7.x-1.0 for Drupal allow remote attackers to hijack the authentication of users for requests that (1) enable list subscriptions via a request to admin/config/services/campaignmonitor/lists/%/enable or (2) disable list subscriptions via a request to admin/config/services/campaignmonitor/lists/%/disable. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site).

    Published: 15 Jun 2015
    3.5
    Low

    CVE-2015-4365

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Taxonomy Accordion module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to taxonomy terms.

    Published: 15 Jun 2015
    3.5
    Low

    CVE-2015-4373

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the OG tabs module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to nodes posted in an Organic Groups group.

    Published: 15 Jun 2015
    3.5
    Low

    CVE-2015-4381

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "Administer own invoices" permission to inject arbitrary web script or HTML via unspecified vectors involving nodes of the "Invoice" content type.

    Published: 15 Jun 2015
    2.6
    Low

    CVE-2015-4388

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Current Search Links module 7.x-1.x before 7.x-1.1 for Drupal, when the "Append the keywords passed by the user to the list" option is disabled, allows remote attackers to inject arbitrary web script or HTML via a crafted search query.

    Published: 15 Jun 2015
    4
    Medium

    CVE-2015-4389

    Last Modified: 12 Apr 2025

    The Open Graph Importer (og_tag_importer) 7.x-1.x for Drupal does not properly check the create permission for content types created during import, which allows remote authenticated users to bypass intended restrictions by leveraging the "import og_tag_importer" permission.

    Published: 15 Jun 2015
    6.8
    Medium

    CVE-2015-4397

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Node Template module for Drupal allows remote attackers to hijack the authentication of users with the "access node template" permission for requests that delete node templates via unspecified vectors.

    Published: 15 Jun 2015
    4.3
    Medium

    CVE-2015-4347

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the inLinks Integration module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified path arguments.

    Published: 15 Jun 2015
    5
    Medium

    CVE-2015-4344

    Last Modified: 12 Apr 2025

    The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vectors related to page caching.

    Published: 15 Jun 2015
    5
    Medium

    CVE-2015-4345

    Last Modified: 12 Apr 2025

    The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for Drupal caches pages for authenticated requests, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 15 Jun 2015
    2.6
    Low

    CVE-2015-4346

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the SMS Framework module 6.x-1.x before 6.x-1.1 for Drupal, when the "Send to phone" submodule is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to message previews.

    Published: 15 Jun 2015