CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2014-6222

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.

    Published: 7 Jun 2015
    4
    Medium

    CVE-2014-8887

    Last Modified: 12 Apr 2025

    IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.0.5, and 9.1.1.x before 9.1.1.2 allows remote authenticated users to upload arbitrary GIFAR files, and consequently modify data, via unspecified vectors.

    Published: 7 Jun 2015
    5
    Medium

    CVE-2015-0770

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in Cisco TelePresence TC 6.x before 6.3.4 and 7.x before 7.3.3 on Integrator C SX20 devices allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL, aka Bug ID CSCut79341.

    Published: 7 Jun 2015
    6.8
    Medium

    CVE-2015-0541

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in EMC RSA Web Threat Detection before 5.1 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 5 Jun 2015
    7.2
    High

    CVE-2015-2124

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Easy Setup Wizard in HP ThinPro Linux 4.1 through 5.1 and Smart Zero Core 4.3 and 4.4 allows local users to bypass intended access restrictions and gain privileges via unknown vectors.

    Published: 5 Jun 2015
    6.4
    Medium

    CVE-2015-2950

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Brandon Bowles Open Explorer application before 0.254 Beta for Android allows remote attackers to write to arbitrary files via a crafted filename.

    Published: 5 Jun 2015
    5
    Medium

    CVE-2015-2951

    Last Modified: 12 Apr 2025

    JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens.

    Published: 5 Jun 2015
    6.4
    Medium

    CVE-2014-9201

    Last Modified: 12 Apr 2025

    Beckwith Electric M-6200 Digital Voltage Regulator Control with firmware before D-0198V04.07.00, M-6200A Digital Voltage Regulator Control with firmware before D-0228V02.01.07, M-2001D Digital Tapchanger Control with firmware before D-0214V01.10.04, M-6283A Three Phase Digital Capacitor Bank Control with firmware before D-0346V03.00.02, M-6280A Digital Capacitor Bank Control with firmware before D-0254V03.05.05, and M-6280 Digital Capacitor Bank Control do not properly generate TCP initial sequence number (ISN) values, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value.

    Published: 5 Jun 2015
    6.8
    Medium

    CVE-2015-1000

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the OpenForIPCamTest method in the RTSPVIDEO.rtspvideoCtrl.1 (aka SStreamVideo) ActiveX control in Moxa SoftCMS before 1.3 allows remote attackers to execute arbitrary code via the StrRtspPath parameter.

    Published: 5 Jun 2015
    6.8
    Medium

    CVE-2015-3950

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to hijack the authentication of admins for requests that select a different default admin user via a GET request.

    Published: 5 Jun 2015
    5.5
    Medium

    CVE-2015-3211

    Last Modified: 20 Apr 2025

    php-fpm allows local users to write to or create arbitrary files via a symlink attack.

    Published: 5 Jun 2015
    4
    Medium

    CVE-2015-3158

    Last Modified: 12 Apr 2025

    The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not properly check role based authorization, which allows remote authenticated users to gain access to restricted application resources via a (1) direct request or (2) request through an SP initiated flow.

    Published: 5 Jun 2015
    4.3
    Medium

    CVE-2015-0766

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in the Management Center component in Cisco FireSIGHT System Software 6.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug IDs CSCus93566, CSCut31557, and CSCut47196.

    Published: 4 Jun 2015
    5
    Medium

    CVE-2015-0763

    Last Modified: 12 Apr 2025

    Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session information via a crafted URL, aka Bug ID CSCuu60338.

    Published: 4 Jun 2015
    5
    Medium

    CVE-2015-0764

    Last Modified: 12 Apr 2025

    Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka Bug ID CSCus95603.

    Published: 4 Jun 2015
    5
    Medium

    CVE-2015-0765

    Last Modified: 12 Apr 2025

    Cisco ONS 15454 System Software 10.30 and 10.301 allows remote attackers to cause a denial of service (tNetTask CPU consumption or card reset) via a flood of (1) IP or (2) Ethernet traffic, aka Bug ID CSCus57263.

    Published: 4 Jun 2015
    4
    Medium

    CVE-2015-0760

    Last Modified: 12 Apr 2025

    The IKEv1 implementation in Cisco ASA Software 7.x, 8.0.x, 8.1.x, and 8.2.x before 8.2.2.13 allows remote authenticated users to bypass XAUTH authentication via crafted IKEv1 packets, aka Bug ID CSCus47259.

    Published: 4 Jun 2015
    7.2
    High

    CVE-2015-0761

    Last Modified: 12 Apr 2025

    Cisco AnyConnect Secure Mobility Client before 3.1(8009) and 4.x before 4.0(2052) on Linux does not properly implement unspecified internal functions, which allows local users to obtain root privileges via crafted vpnagent options, aka Bug ID CSCus86790.

    Published: 4 Jun 2015
    4.3
    Medium

    CVE-2015-0762

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) for Microsoft Outlook allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu51400.

    Published: 4 Jun 2015
    10
    Critical

    CVE-2015-4335

    Last Modified: 12 Apr 2025

    Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.

    Published: 4 Jun 2015
    7.5
    High

    CVE-2015-4410

    Last Modified: 21 Nov 2024

    The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site scripting (XSS) attack via a crafted string.

    Published: 4 Jun 2015
    7.5
    High

    CVE-2015-4411

    Last Modified: 21 Nov 2024

    The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-2015-4410.

    Published: 4 Jun 2015
    9.8
    Critical

    CVE-2015-4412

    Last Modified: 21 Nov 2024

    BSON injection vulnerability in the legal? function in BSON (bson-ruby) gem before 3.0.4 for Ruby allows remote attackers to cause a denial of service (resource consumption) or inject arbitrary data via a crafted string.

    Published: 4 Jun 2015
    4.9
    Medium

    CVE-2015-4692

    Last Modified: 12 Apr 2025

    The kvm_apic_has_events function in arch/x86/kvm/lapic.h in the Linux kernel through 4.1.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging /dev/kvm access for an ioctl call.

    Published: 4 Jun 2015
    6.5
    Medium

    CVE-2015-4038

    Last Modified: 12 Apr 2025

    The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php.

    Published: 3 Jun 2015
    4.3
    Medium

    CVE-2015-5523

    Last Modified: 12 Apr 2025

    The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.

    Published: 3 Jun 2015
    6.8
    Medium

    CVE-2015-5522

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.

    Published: 3 Jun 2015
    7.5
    High

    CVE-2015-3217

    Last Modified: 12 Apr 2025

    PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)+$/.

    Published: 3 Jun 2015
    4.3
    Medium

    CVE-2015-2944

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse.

    Published: 2 Jun 2015
    3.6
    Low

    CVE-2015-4156

    Last Modified: 12 Apr 2025

    GNU Parallel before 20150522 (Nepal), when using (1) --cat or (2) --fifo with --sshlogin, allows local users to write to arbitrary files via a symlink attack on a temporary file.

    Published: 2 Jun 2015
    7.5
    High

    CVE-2015-4160

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in SAP ASE Database Platform allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Notes: 2152278.

    Published: 2 Jun 2015
    5
    Medium

    CVE-2014-0999

    Last Modified: 12 Apr 2025

    Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and hijack sessions by reading the jsessionid parameter in the Referrer HTTP header.

    Published: 2 Jun 2015
    5
    Medium

    CVE-2015-2278

    Last Modified: 12 Apr 2025

    The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to look-ups of non-simple codes, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.

    Published: 2 Jun 2015
    7.5
    High

    CVE-2015-2282

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2124806, 2121661, 2127995, and 2125316.

    Published: 2 Jun 2015
    5.8
    Medium

    CVE-2015-4094

    Last Modified: 12 Apr 2025

    The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Jun 2015
    4
    Medium

    CVE-2014-8391

    Last Modified: 12 Apr 2025

    The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information from other users' sessions via a large number of requests.

    Published: 2 Jun 2015
    6.8
    Medium

    CVE-2015-0759

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cisco Headend Digital Broadband Delivery System allows remote attackers to hijack the authentication of arbitrary users.

    Published: 2 Jun 2015
    10
    Critical

    CVE-2015-0850

    Last Modified: 12 Apr 2025

    The Git plugin for FusionForge before 6.0rc4 allows remote attackers to execute arbitrary code via an unspecified parameter when creating a secondary Git repository.

    Published: 2 Jun 2015
    6.5
    Medium

    CVE-2015-1945

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Reference Data Management component in IBM InfoSphere Master Data Management 10.1, 11.0, 11.3 before FP3, and 11.4 allows remote authenticated users to gain privileges via unknown vectors.

    Published: 2 Jun 2015
    4.3
    Medium

    CVE-2015-4050

    Last Modified: 12 Apr 2025

    FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

    Published: 2 Jun 2015
    3.6
    Low

    CVE-2015-4155

    Last Modified: 12 Apr 2025

    GNU Parallel before 20150422, when using (1) --pipe, (2) --tmux, (3) --cat, (4) --fifo, or (5) --compress, allows local users to write to arbitrary files via a symlink attack on a temporary file.

    Published: 2 Jun 2015
    5
    Medium

    CVE-2015-4157

    Last Modified: 12 Apr 2025

    SAP Content Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2127995.

    Published: 2 Jun 2015
    5
    Medium

    CVE-2015-4158

    Last Modified: 12 Apr 2025

    SAP ABAP & Java Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2121661.

    Published: 2 Jun 2015
    7.5
    High

    CVE-2015-4159

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in SAP HANA Web-based Development Workbench allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Notes 2153892.

    Published: 2 Jun 2015
    7.5
    High

    CVE-2015-4161

    Last Modified: 12 Apr 2025

    SAP Afaria does not properly restrict access to unspecified functionality, which allows remote attackers to obtain sensitive information, gain privileges, or have other unspecified impact via unknown vectors, SAP Security Note 2155690.

    Published: 2 Jun 2015
    4
    Medium

    CVE-2015-4162

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to obtain sensitive information via crafted XML data.

    Published: 2 Jun 2015
    7.8
    High

    CVE-2015-4104

    Last Modified: 12 Apr 2025

    Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (unexpected interrupt and host crash) via unspecified vectors.

    Published: 2 Jun 2015
    7.2
    High

    CVE-2015-1805

    Last Modified: 12 Apr 2025

    The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun."

    Published: 2 Jun 2015
    7.2
    High

    CVE-2015-3213

    Last Modified: 12 Apr 2025

    The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via certain (1) mouse or (2) touch gestures.

    Published: 2 Jun 2015
    4.9
    Medium

    CVE-2015-4105

    Last Modified: 12 Apr 2025

    Xen 3.3.x through 4.5.x enables logging for PCI MSI-X pass-through error messages, which allows local x86 HVM guests to cause a denial of service (host disk consumption) via certain invalid operations.

    Published: 2 Jun 2015