CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2015-0743

    Last Modified: 12 Apr 2025

    Cisco Headend System Release allows remote attackers to cause a denial of service (DHCP and TFTP outage) via a flood of crafted UDP traffic, aka Bug ID CSCus04097.

    Published: 30 May 2015
    7.8
    High

    CVE-2015-0744

    Last Modified: 12 Apr 2025

    Cisco DTA Control System (DTACS) 4.0.0.9 and Cisco Headend System Release allow remote attackers to cause a denial of service (CPU and memory consumption, and TCP service outage) via (1) a SYN flood or (2) another type of TCP traffic flood, aka Bug IDs CSCus50642, CSCus50662, CSCus50625, CSCus50657, and CSCus68315.

    Published: 30 May 2015
    4.3
    Medium

    CVE-2015-0747

    Last Modified: 12 Apr 2025

    Cisco Conductor for Videoscape 3.0 and Cisco Headend System Release allow remote attackers to inject arbitrary cookies via a crafted HTTP request, aka Bug ID CSCuh25408.

    Published: 30 May 2015
    4
    Medium

    CVE-2015-0758

    Last Modified: 12 Apr 2025

    The web-based user interface in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCus97452.

    Published: 30 May 2015
    9.1
    Critical

    CVE-2015-4068

    Last Modified: 21 Apr 2026

    Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.

    Published: 29 May 2015
    4.3
    Medium

    CVE-2015-0752

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27635.

    Published: 29 May 2015
    6.8
    Medium

    CVE-2015-0755

    Last Modified: 12 Apr 2025

    The Posture module for Cisco Identity Services Engine (ISE), as distributed in Cisco AnyConnect Secure Mobility Client 4.0(64), allows local users to gain privileges via unspecified commands, aka Bug ID CSCut05797.

    Published: 29 May 2015
    7.5
    High

    CVE-2015-0754

    Last Modified: 12 Apr 2025

    Cisco Finesse 10.5(1) allows remote authenticated users to obtain sensitive information or cause a denial of service (CPU and memory consumption) via a crafted XML document, aka Bug ID CSCut95810.

    Published: 29 May 2015
    7.8
    High

    CVE-2013-7441

    Last Modified: 12 Apr 2025

    The modern style negotiation in Network Block Device (nbd-server) 2.9.22 through 3.3 allows remote attackers to cause a denial of service (root process termination) by (1) closing the connection during negotiation or (2) specifying a name for a non-existent export.

    Published: 29 May 2015
    4
    Medium

    CVE-2015-3994

    Last Modified: 12 Apr 2025

    The grant.xsfunc application in testApps/grantAccess/ in the XS Engine in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to spoof log entries via a crafted request, aka SAP Security Note 2109818.

    Published: 29 May 2015
    10
    Critical

    CVE-2014-9727

    Last Modified: 12 Apr 2025

    AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.

    Published: 29 May 2015
    2.1
    Low

    CVE-2015-0200

    Last Modified: 12 Apr 2025

    IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x before 7.0.0.8 IF2 allows local users to obtain sensitive database information via unspecified vectors.

    Published: 29 May 2015
    7.8
    High

    CVE-2015-0751

    Last Modified: 12 Apr 2025

    Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to cause a denial of service via crafted packets, aka Bug ID CSCus81800.

    Published: 29 May 2015
    6.8
    Medium

    CVE-2015-0753

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Cisco Unified Email Interaction Manager (EIM) and Unified Web Interaction Manager (WIM) 9.0(2) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuu30028.

    Published: 29 May 2015
    6.1
    Medium

    CVE-2015-0756

    Last Modified: 12 Apr 2025

    Cisco Wireless LAN Controller (WLC) devices with software 7.4(1.1) allow remote attackers to cause a denial of service (wireless-networking outage) via crafted TCP traffic on the local network, aka Bug ID CSCug67104.

    Published: 29 May 2015
    5
    Medium

    CVE-2015-0757

    Last Modified: 12 Apr 2025

    The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers to obtain sensitive information by reading web pages, as demonstrated by MnT reports, aka Bug ID CSCuq23140.

    Published: 29 May 2015
    7.8
    High

    CVE-2015-0847

    Last Modified: 12 Apr 2025

    nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of service (deadlock) via unspecified vectors.

    Published: 29 May 2015
    4
    Medium

    CVE-2015-3995

    Last Modified: 12 Apr 2025

    SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote authenticated users to read arbitrary files via an IMPORT FROM SQL statement, aka SAP Security Note 2109565.

    Published: 29 May 2015
    10
    Critical

    CVE-2015-4031

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in saveFile.jsp in the development installation in Visual Mining NetChart allows remote attackers to write to arbitrary files via unspecified vectors.

    Published: 29 May 2015
    10
    Critical

    CVE-2015-4032

    Last Modified: 12 Apr 2025

    projectContents.jsp in the Developer tools in Visual Mining NetCharts Server allows remote attackers to rename arbitrary files, and consequently execute them, via unspecified vectors.

    Published: 29 May 2015
    10
    Critical

    CVE-2015-4059

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the License Server (LicenseServer.exe) in Wavelink Terminal Emulation (TE) allows remote attackers to execute arbitrary code via a large HTTP header.

    Published: 29 May 2015
    10
    Critical

    CVE-2015-4060

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the TermProxy (WLTermProxyService.exe) service in Wavelink ConnectPro allows remote attackers to execute arbitrary code via a large HTTP header.

    Published: 29 May 2015
    10
    Critical

    CVE-2015-4067

    Last Modified: 12 Apr 2025

    Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted template string specifiers in a serialized object, which triggers a heap-based buffer overflow.

    Published: 29 May 2015
    7.8
    High

    CVE-2015-4069

    Last Modified: 12 Apr 2025

    The EdgeServiceImpl web service in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive credentials via a crafted SOAP request to the (1) getBackupPolicy or (2) getBackupPolicies method.

    Published: 29 May 2015
    7.5
    High

    CVE-2015-4137

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL commands via the program parameter.

    Published: 29 May 2015
    4.3
    Medium

    CVE-2015-3904

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in roomcloud.php in the Roomcloud plugin before 1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) pin, (2) start_day, (3) start_month, (4) start_year, (5) end_day, (6) end_month, (7) end_year, (8) lang, (9) adults, or (10) children parameter.

    Published: 29 May 2015
    2.1
    Low

    CVE-2015-3218

    Last Modified: 12 Apr 2025

    The authentication_agent_new function in polkitbackend/polkitbackendinteractiveauthority.c in PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (NULL pointer dereference and polkitd daemon crash) by calling RegisterAuthenticationAgent with an invalid object path.

    Published: 29 May 2015
    8.1
    High

    CVE-2015-0839

    Last Modified: 20 Apr 2025

    The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by leveraging use of a short GPG key id from a keyserver to verify print plugin downloads.

    Published: 29 May 2015
    4.6
    Medium

    CVE-2015-4625

    Last Modified: 12 Apr 2025

    Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a duplicate cookie value.

    Published: 29 May 2015
    9
    Critical

    CVE-2014-6628

    Last Modified: 12 Apr 2025

    Aruba Networks ClearPass Policy Manager (CPPM) before 6.5.0 allows remote administrators to execute arbitrary code via unspecified vectors.

    Published: 28 May 2015
    4.3
    Medium

    CVE-2015-4135

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 28 May 2015
    9
    Critical

    CVE-2015-1550

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administrators to execute arbitrary files via unspecified vectors.

    Published: 28 May 2015
    4.3
    Medium

    CVE-2015-1389

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary web script or HTML via the username parameter to tips/tipsLoginSubmit.action.

    Published: 28 May 2015
    4
    Medium

    CVE-2015-1551

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.4 allows remote administrators to read arbitrary files via unspecified vectors.

    Published: 28 May 2015
    5.8
    Medium

    CVE-2015-4134

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in goto.php in phpwind 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

    Published: 28 May 2015
    6.5
    Medium

    CVE-2015-1392

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 May 2015
    4.3
    Medium

    CVE-2015-4084

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value_ parameter in a check_stat action to wp-admin/admin-ajax.php.

    Published: 28 May 2015
    4.3
    Medium

    CVE-2015-4127

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.

    Published: 28 May 2015
    3.5
    Low

    CVE-2015-4132

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 May 2015
    7.5
    High

    CVE-2015-4133

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.

    Published: 28 May 2015
    7.8
    High

    CVE-2015-1157

    Last Modified: 12 Apr 2025

    CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.

    Published: 28 May 2015
    4.3
    Medium

    CVE-2015-3216

    Last Modified: 12 Apr 2025

    Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 and other products, allows remote attackers to cause a denial of service (application crash) by establishing many TLS sessions to a multithreaded server, leading to use of a negative value for a certain length field.

    Published: 28 May 2015
    6.5
    Medium

    CVE-2015-4598

    Last Modified: 12 Apr 2025

    PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument save method or (2) the GD imagepsloadfont function, as demonstrated by a filename\0.html attack that bypasses an intended configuration in which client users may write to only .html files.

    Published: 28 May 2015
    7.5
    High

    CVE-2015-8895

    Last Modified: 20 Apr 2025

    Integer overflow in coders/icon.c in ImageMagick 6.9.1-3 and later allows remote attackers to cause a denial of service (application crash) via a crafted length value, which triggers a buffer overflow.

    Published: 28 May 2015
    6.5
    Medium

    CVE-2015-4062

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.

    Published: 27 May 2015
    5.8
    Medium

    CVE-2015-3922

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter.

    Published: 27 May 2015
    3.5
    Low

    CVE-2015-4063

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.

    Published: 27 May 2015
    3.5
    Low

    CVE-2015-3921

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in contact.php in Coppermine Photo Gallery before 1.5.36 allows remote authenticated users to inject arbitrary web script or HTML via the referer parameter.

    Published: 27 May 2015
    6.5
    Medium

    CVE-2015-4064

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.

    Published: 27 May 2015
    3.5
    Low

    CVE-2015-4065

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-new.php.

    Published: 27 May 2015