CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2015-3080

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 12 May 2015
    6.4
    Medium

    CVE-2015-3082

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow remote attackers to bypass intended restrictions on filesystem write operations via unspecified vectors, a different vulnerability than CVE-2015-3083 and CVE-2015-3085.

    Published: 12 May 2015
    6.4
    Medium

    CVE-2015-3083

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow remote attackers to bypass intended restrictions on filesystem write operations via unspecified vectors, a different vulnerability than CVE-2015-3082 and CVE-2015-3085.

    Published: 12 May 2015
    10
    Critical

    CVE-2015-3086

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-3077 and CVE-2015-3084.

    Published: 12 May 2015
    10
    Critical

    CVE-2015-3087

    Last Modified: 12 Apr 2025

    Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 12 May 2015
    10
    Critical

    CVE-2015-3088

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 12 May 2015
    5
    Medium

    CVE-2015-3091

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2015-3092.

    Published: 12 May 2015
    5
    Medium

    CVE-2015-3092

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than CVE-2015-3091.

    Published: 12 May 2015
    10
    Critical

    CVE-2015-3093

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3078, CVE-2015-3089, and CVE-2015-3090.

    Published: 12 May 2015
    7.8
    High

    CVE-2015-3810

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-websocket.c in the WebSocket dissector in Wireshark 1.12.x before 1.12.5 uses a recursive algorithm, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted packet.

    Published: 12 May 2015
    5
    Medium

    CVE-2015-3811

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, a different vulnerability than CVE-2015-2188.

    Published: 12 May 2015
    7.8
    High

    CVE-2015-3812

    Last Modified: 12 Apr 2025

    Multiple memory leaks in the x11_init_protocol function in epan/dissectors/packet-x11.c in the X11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 allow remote attackers to cause a denial of service (memory consumption) via a crafted packet.

    Published: 12 May 2015
    5
    Medium

    CVE-2015-3813

    Last Modified: 12 Apr 2025

    The fragment_add_work function in epan/reassemble.c in the packet-reassembly feature in Wireshark 1.12.x before 1.12.5 does not properly determine the defragmentation state in a case of an insufficient snapshot length, which allows remote attackers to cause a denial of service (memory consumption) via a crafted packet.

    Published: 12 May 2015
    5
    Medium

    CVE-2015-3814

    Last Modified: 12 Apr 2025

    The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 interpret a zero value as a length rather than an error condition, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

    Published: 12 May 2015
    7.5
    High

    CVE-2015-1831

    Last Modified: 12 Apr 2025

    The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors.

    Published: 11 May 2015
    7.5
    High

    CVE-2014-8162

    Last Modified: 12 Apr 2025

    XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified impact via unknown vectors.

    Published: 11 May 2015
    4.3
    Medium

    CVE-2015-3885

    Last Modified: 12 Apr 2025

    Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

    Published: 11 May 2015
    7.5
    High

    CVE-2015-2156

    Last Modified: 20 Apr 2025

    Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.

    Published: 9 May 2015
    4.6
    Medium

    CVE-2015-5706

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.

    Published: 9 May 2015
    4.3
    Medium

    CVE-2015-2347

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Huawei SEQ Analyst before V200R002C03LG0001CP0022 allows remote attackers to inject arbitrary web script or HTML via the command XML element in the req parameter to flexdata.action in (1) common/, (2) monitor/, or (3) psnpm/ or the (4) module XML element in the req parameter to flexdata.action in monitor/.

    Published: 8 May 2015
    3.5
    Low

    CVE-2015-3011

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the contacts application in ownCloud Server Community Edition before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted contact.

    Published: 8 May 2015
    6
    Medium

    CVE-2015-3013

    Last Modified: 12 Apr 2025

    ownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbitrary files via a file path with UTF-8 encoding, as demonstrated by uploading a .htaccess file.

    Published: 8 May 2015
    4.3
    Medium

    CVE-2015-3012

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in WebODF before 0.5.5, as used in ownCloud, allow remote attackers to inject arbitrary web script or HTML via a (1) style or (2) font name or (3) javascript or (4) data URI.

    Published: 8 May 2015
    4.3
    Medium

    CVE-2014-9716

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebODF before 0.5.4 allows remote attackers to inject arbitrary web script or HTML via a file name.

    Published: 8 May 2015
    4
    Medium

    CVE-2014-0919

    Last Modified: 12 Apr 2025

    IBM DB2 9.5 through 10.5 on Linux, UNIX, and Windows stores passwords during the processing of certain SQL statements by the monitoring and audit facilities, which allows remote authenticated users to obtain sensitive information via commands associated with these facilities.

    Published: 8 May 2015
    4
    Medium

    CVE-2015-1907

    Last Modified: 12 Apr 2025

    The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4 before 8.1.4.7 allows remote authenticated users to read cookies via unspecified vectors.

    Published: 8 May 2015
    6.8
    Medium

    CVE-2015-1152

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1153 and CVE-2015-1154.

    Published: 8 May 2015
    6.8
    Medium

    CVE-2015-1153

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1152 and CVE-2015-1154.

    Published: 8 May 2015
    6.8
    Medium

    CVE-2015-1154

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1152 and CVE-2015-1153.

    Published: 8 May 2015
    4.3
    Medium

    CVE-2015-1155

    Last Modified: 12 Apr 2025

    The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to bypass the Same Origin Policy and read arbitrary files via a crafted web site.

    Published: 8 May 2015
    4.3
    Medium

    CVE-2015-1156

    Last Modified: 12 Apr 2025

    The page-loading implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, does not properly handle the rel attribute in an A element, which allows remote attackers to bypass the Same Origin Policy for a link's target, and spoof the user interface, via a crafted web site.

    Published: 8 May 2015
    5.4
    Medium

    CVE-2015-3610

    Last Modified: 12 Apr 2025

    The Siemens HomeControl for Room Automation application before 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information or modify data via a crafted certificate.

    Published: 7 May 2015
    6.5
    Medium

    CVE-2015-0715

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and CSCut33608.

    Published: 7 May 2015
    5
    Medium

    CVE-2015-0531

    Last Modified: 12 Apr 2025

    EMC SourceOne Email Management before 7.2 does not have a lockout mechanism for invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 7 May 2015
    9.3
    Critical

    CVE-2015-0538

    Last Modified: 12 Apr 2025

    ftagent.exe in EMC AutoStart 5.4.x and 5.5.x before 5.5.0.508 HF4 allows remote attackers to execute arbitrary commands via crafted packets.

    Published: 7 May 2015
    10
    Critical

    CVE-2015-0701

    Last Modified: 12 Apr 2025

    Cisco UCS Central Software before 1.3(1a) allows remote attackers to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCut46961.

    Published: 7 May 2015
    6.8
    Medium

    CVE-2015-0716

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the CUCReports page in Cisco Unity Connection 11.0(0.98000.225) and 11.0(0.98000.332) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut33659.

    Published: 7 May 2015
    7.2
    High

    CVE-2015-3627

    Last Modified: 12 Apr 2025

    Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.

    Published: 7 May 2015
    7.8
    High

    CVE-2015-3629

    Last Modified: 12 Apr 2025

    Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.

    Published: 7 May 2015
    6.5
    Medium

    CVE-2015-5248

    Last Modified: 20 Apr 2025

    Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.

    Published: 7 May 2015
    5.5
    Medium

    CVE-2015-3182

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 7 May 2015
    7.2
    High

    CVE-2015-3630

    Last Modified: 12 Apr 2025

    Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.

    Published: 7 May 2015
    3.6
    Low

    CVE-2015-3631

    Last Modified: 12 Apr 2025

    Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.

    Published: 7 May 2015
    7.5
    High

    CVE-2015-1916

    Last Modified: 27 May 2026

    Unspecified vulnerability in IBM Java 8 before SR1 allows remote attackers to cause a denial of service via unknown vectors related to SSL/TLS and the Secure Socket Extension provider.

    Published: 6 May 2015
    9.8
    Critical

    CVE-2015-0192

    Last Modified: 27 May 2026

    Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Virtual Machine.

    Published: 6 May 2015
    5
    Medium

    CVE-2015-1914

    Last Modified: 12 Apr 2025

    IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permission checks" and obtain sensitive information via vectors related to the Java Virtual Machine.

    Published: 6 May 2015
    5.5
    Medium

    CVE-2015-4176

    Last Modified: 12 Apr 2025

    fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users to read arbitrary files by leveraging user-namespace root access for deletion of a file or directory.

    Published: 6 May 2015
    7.5
    High

    CVE-2015-3198

    Last Modified: 20 Apr 2025

    The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via a "/" at the end of a URL.

    Published: 6 May 2015
    5.5
    Medium

    CVE-2015-3170

    Last Modified: 20 Apr 2025

    selinux-policy when sysctl fs.protected_hardlinks are set to 0 allows local users to cause a denial of service (SSH login prevention) by creating a hardlink to /etc/passwd from a directory named .config, and updating selinux-policy.

    Published: 5 May 2015
    7.5
    High

    CVE-2014-8146

    Last Modified: 12 Apr 2025

    The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via crafted text.

    Published: 5 May 2015