CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2015-4066

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) show_artist_id or (2) show_venue_id parameter in an add action in the gigpress.php page to wp-admin/admin.php.

    Published: 27 May 2015
    8.8
    High

    CVE-2015-9284

    Last Modified: 21 Nov 2024

    The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without user intent, user interaction, or feedback to the user. This permits a secondary account to be able to sign into the web application as the primary account.

    Published: 27 May 2015
    6.8
    Medium

    CVE-2015-3902

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

    Published: 26 May 2015
    5
    Medium

    CVE-2015-3906

    Last Modified: 12 Apr 2025

    The logcat_dump_text function in wiretap/logcat.c in the Android Logcat file parser in Wireshark 1.12.x before 1.12.5 does not properly handle a lack of \0 termination, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted message in a packet, a different vulnerability than CVE-2015-3815.

    Published: 26 May 2015
    7.5
    High

    CVE-2015-0986

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in Moxa VPort ActiveX SDK Plus before 2.8 allow remote attackers to insert assembly-code lines via vectors involving a regkey (1) set or (2) get command.

    Published: 26 May 2015
    4.3
    Medium

    CVE-2015-3903

    Last Modified: 12 Apr 2025

    libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 May 2015
    7.5
    High

    CVE-2015-4091

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in SAP NetWeaver AS Java 7.4 allows remote attackers to send TCP requests to intranet servers or possibly have unspecified other impact via an XML request to tc~sld~wd~main/Main, related to "CIM UPLOAD," aka SAP Security Note 2090851.

    Published: 26 May 2015
    7.5
    High

    CVE-2015-4092

    Last Modified: 12 Apr 2025

    Buffer overflow in the XComms process in SAP Afaria 7.00.6620.2 SP5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request, aka SAP Security Note 2153690.

    Published: 26 May 2015
    6.5
    Medium

    CVE-2015-1013

    Last Modified: 12 Apr 2025

    OSIsoft PI AF 2.6 and 2.7 and PI SQL for AF 2.1.2.19 do not ensure that the PI SQL (AF) Trusted Users group lacks the Everyone account, which allows remote authenticated users to bypass intended command restrictions via SQL statements.

    Published: 26 May 2015
    6.5
    Medium

    CVE-2015-1008

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Emerson AMS Device Manager before 13 allows remote authenticated users to gain privileges via malformed input.

    Published: 26 May 2015
    4.3
    Medium

    CVE-2015-0961

    Last Modified: 12 Apr 2025

    Barracuda Web Filter before 8.1.0.005, when SSL Inspection is enabled, does not verify X.509 certificates from upstream SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 25 May 2015
    4.3
    Medium

    CVE-2015-0962

    Last Modified: 12 Apr 2025

    Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate's trust relationship.

    Published: 25 May 2015
    6.8
    Medium

    CVE-2015-2946

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the Open CAD Format Council SXF common library before 3.30 allows remote attackers to execute arbitrary code via a crafted CAD file.

    Published: 25 May 2015
    6.5
    Medium

    CVE-2015-0540

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the xAdmin interface in EMC Document Sciences xPression 4.2 before P44 and 4.5 SP1 before P03 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 25 May 2015
    7.5
    High

    CVE-2015-0935

    Last Modified: 12 Apr 2025

    Bomgar Remote Support before 15.1.1 allows remote attackers to execute arbitrary PHP code via crafted serialized data to unspecified PHP scripts.

    Published: 25 May 2015
    7.5
    High

    CVE-2015-2945

    Last Modified: 12 Apr 2025

    mt-phpincgi.php in Hajime Fujimoto mt-phpincgi before 2015-05-15 does not properly restrict URLs, which allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted request, as exploited in the wild in May 2015.

    Published: 25 May 2015
    10
    Critical

    CVE-2015-2110

    Last Modified: 12 Apr 2025

    Buffer overflow in HP LoadRunner 11.52 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 25 May 2015
    4
    Medium

    CVE-2015-2118

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Secure Pull Print and Security Pull Print components in HP Access Control (AC) Software 12.x through 14.x before 14.1.2 allows remote authenticated users to obtain sensitive information via unknown vectors.

    Published: 25 May 2015
    7.8
    High

    CVE-2015-2121

    Last Modified: 12 Apr 2025

    HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename in a URL to the (1) HttpServlet or (2) NetworkEditorController component, aka ZDI-CAN-2569.

    Published: 25 May 2015
    9
    Critical

    CVE-2015-2123

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP NonStop Safeguard Security Software H06.x, L15.02, and J06.x before J06.19 allows remote authenticated users to gain privileges by leveraging Expand access.

    Published: 25 May 2015
    3.5
    Low

    CVE-2014-6192

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix10, 6.0.5 before 6.0.5.6, and 6.0.5.5a before 6.0.5.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 25 May 2015
    3.5
    Low

    CVE-2015-0168

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 May 2015
    5
    Medium

    CVE-2014-8927

    Last Modified: 12 Apr 2025

    Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8926.

    Published: 25 May 2015
    4
    Medium

    CVE-2015-0169

    Last Modified: 12 Apr 2025

    IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to inject arguments via unspecified vectors.

    Published: 25 May 2015
    6.8
    Medium

    CVE-2014-4774

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 allows remote attackers to hijack the authentication of arbitrary users via vectors involving a FRAME element.

    Published: 25 May 2015
    4.3
    Medium

    CVE-2014-4778

    Last Modified: 12 Apr 2025

    IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which allows remote attackers to conduct clickjacking attacks via vectors involving a FRAME element.

    Published: 25 May 2015
    5
    Medium

    CVE-2014-6190

    Last Modified: 12 Apr 2025

    The log viewer in IBM Workload Deployer 3.1 before 3.1.0.7 allows remote attackers to obtain sensitive information via a direct request for the URL of a log document.

    Published: 25 May 2015
    5
    Medium

    CVE-2014-8926

    Last Modified: 12 Apr 2025

    Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for Software Use Analysis 9; and Tivoli Asset Discovery for Distributed 7.2.2 and 7.5 allows remote attackers to cause a denial of service (CPU consumption or application crash) via a crafted XML query, a different vulnerability than CVE-2014-8927.

    Published: 25 May 2015
    6.5
    Medium

    CVE-2015-0161

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 25 May 2015
    7.5
    High

    CVE-2015-0120

    Last Modified: 12 Apr 2025

    Buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 has unspecified impact and remote attack vectors.

    Published: 25 May 2015
    6.8
    Medium

    CVE-2015-0140

    Last Modified: 12 Apr 2025

    An unspecified ActiveX control in IBM SPSS Statistics 22.0 through FP1 on 32-bit platforms allows remote attackers to execute arbitrary code via a crafted HTML document.

    Published: 25 May 2015
    3.5
    Low

    CVE-2015-0156

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.6.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 25 May 2015
    9
    Critical

    CVE-2015-0160

    Last Modified: 12 Apr 2025

    IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to execute arbitrary commands with SYSTEM privileges via unspecified vectors.

    Published: 25 May 2015
    2.1
    Low

    CVE-2015-0170

    Last Modified: 12 Apr 2025

    IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows local users to obtain sensitive information by reading cached data.

    Published: 25 May 2015
    5.5
    Medium

    CVE-2015-0171

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to write to arbitrary files via unspecified vectors.

    Published: 25 May 2015
    5.5
    Medium

    CVE-2015-0180

    Last Modified: 12 Apr 2025

    The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote authenticated users to bypass intended restrictions on job creation and modification via unspecified vectors.

    Published: 25 May 2015
    8.7
    High

    CVE-2015-2120

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP SiteScope 11.1x before 11.13, 11.2x before 11.24.391, and 11.3x before 11.30.521 allows remote authenticated users to gain privileges via unknown vectors, aka ZDI-CAN-2567.

    Published: 25 May 2015
    7.8
    High

    CVE-2015-2122

    Last Modified: 12 Apr 2025

    The REST layer on HP SDN VAN Controller devices 2.5 and earlier allows remote attackers to cause a denial of service via network traffic to the REST port.

    Published: 25 May 2015
    8.3
    High

    CVE-2014-2174

    Last Modified: 12 Apr 2025

    Cisco TelePresence T, TelePresence TE, and TelePresence TC before 7.1 do not properly implement access control, which allows remote attackers to obtain root privileges by sending packets on the local network and allows physically proximate attackers to obtain root privileges via unspecified vectors, aka Bug ID CSCub67651.

    Published: 25 May 2015
    9
    Critical

    CVE-2015-0713

    Last Modified: 12 Apr 2025

    The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94), Cisco TelePresence MCU Software before 4.4(3.54) and 4.5 before 4.5(1.45), Cisco TelePresence MSE Supervisor Software before 2.3(1.38), Cisco TelePresence Serial Gateway Series Software before 1.0(1.42), Cisco TelePresence Server Software for Hardware before 3.1(1.98), and Cisco TelePresence Server Software for Virtual Machine before 4.1(1.79) allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors, aka Bug IDs CSCul55968, CSCur08993, CSCur15803, CSCur15807, CSCur15825, CSCur15832, CSCur15842, CSCur15850, and CSCur15855.

    Published: 25 May 2015
    7.8
    High

    CVE-2015-0722

    Last Modified: 12 Apr 2025

    The network drivers in Cisco TelePresence T, Cisco TelePresence TE, and Cisco TelePresence TC before 7.3.2 allow remote attackers to cause a denial of service (process restart or device reload) via a flood of crafted IP packets, aka Bug ID CSCuj68952.

    Published: 25 May 2015
    7.3
    High

    CVE-2015-1836

    Last Modified: 12 Apr 2025

    Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect ACLs for ZooKeeper coordination state, which allows remote attackers to cause a denial of service (daemon outage), obtain sensitive information, or modify data via unspecified client traffic.

    Published: 25 May 2015
    6.8
    Medium

    CVE-2015-1894

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 25 May 2015
    5
    Medium

    CVE-2015-1895

    Last Modified: 12 Apr 2025

    IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 relies on client-side code to verify authorization, which allows remote attackers to bypass intended access restrictions by modifying the client behavior.

    Published: 25 May 2015
    10
    Critical

    CVE-2015-1896

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 25 May 2015
    7.8
    High

    CVE-2015-1899

    Last Modified: 12 Apr 2025

    IBM WebSphere Portal 8.5 through CF05 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

    Published: 25 May 2015
    5
    Medium

    CVE-2015-1909

    Last Modified: 12 Apr 2025

    The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary files, and consequently obtain administrative access, via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 25 May 2015
    3.5
    Low

    CVE-2015-1910

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, and 11.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 25 May 2015
    4.3
    Medium

    CVE-2015-1911

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Sterling Order Management 8.5 before HF113, Sterling Selling and Fulfillment Foundation 9.0.0 before FP92, and Sterling Field Sales (SFS) 9.0 before HF7 in IBM Sterling Selling and Fulfillment Suite allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 25 May 2015
    4.3
    Medium

    CVE-2015-1915

    Last Modified: 12 Apr 2025

    The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

    Published: 25 May 2015