CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2015-0298

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the manager web interface in mod_cluster before 1.3.2.Alpha1 allows remote attackers to inject arbitrary web script or HTML via a crafted MCMP message.

    Published: 5 May 2015
    5.5
    Medium

    CVE-2015-3171

    Last Modified: 20 Apr 2025

    sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.

    Published: 5 May 2015
    7.5
    High

    CVE-2014-8147

    Last Modified: 12 Apr 2025

    The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 uses an integer data type that is inconsistent with a header file, which allows remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly execute arbitrary code via crafted text.

    Published: 5 May 2015
    9.8
    Critical

    CVE-2010-5325

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via a long job title.

    Published: 5 May 2015
    5
    Medium

    CVE-2015-4145

    Last Modified: 12 Apr 2025

    The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate a fragment is already being processed, which allows remote attackers to cause a denial of service (memory leak) via a crafted message.

    Published: 4 May 2015
    4.3
    Medium

    CVE-2015-4142

    Last Modified: 12 Apr 2025

    Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.

    Published: 4 May 2015
    5
    Medium

    CVE-2015-4146

    Last Modified: 12 Apr 2025

    The EAP-pwd peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not clear the L (Length) and M (More) flags before determining if a response should be fragmented, which allows remote attackers to cause a denial of service (crash) via a crafted message.

    Published: 4 May 2015
    5.9
    Medium

    CVE-2015-8762

    Last Modified: 20 Apr 2025

    The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packet.

    Published: 4 May 2015
    4
    Medium

    CVE-2015-3646

    Last Modified: 12 Apr 2025

    OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs.

    Published: 4 May 2015
    4.3
    Medium

    CVE-2015-4141

    Last Modified: 12 Apr 2025

    The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow.

    Published: 4 May 2015
    5
    Medium

    CVE-2015-4143

    Last Modified: 12 Apr 2025

    The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) Commit or (2) Confirm message payload.

    Published: 4 May 2015
    5
    Medium

    CVE-2015-4144

    Last Modified: 12 Apr 2025

    The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate that a message is long enough to contain the Total-Length field, which allows remote attackers to cause a denial of service (crash) via a crafted message.

    Published: 4 May 2015
    5
    Medium

    CVE-2015-4695

    Last Modified: 12 Apr 2025

    meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.

    Published: 4 May 2015
    8.1
    High

    CVE-2015-8763

    Last Modified: 20 Apr 2025

    The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message, which triggers an out-of-bounds read.

    Published: 4 May 2015
    8.1
    High

    CVE-2015-8764

    Last Modified: 20 Apr 2025

    Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.

    Published: 4 May 2015
    4.3
    Medium

    CVE-2015-4696

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.

    Published: 3 May 2015
    4.3
    Medium

    CVE-2015-0714

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse Server 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCut53595.

    Published: 2 May 2015
    7.5
    High

    CVE-2015-4017

    Last Modified: 20 Apr 2025

    Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.

    Published: 2 May 2015
    4.9
    Medium

    CVE-2015-3636

    Last Modified: 12 Apr 2025

    The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) by leveraging the ability to make a SOCK_DGRAM socket system call for the IPPROTO_ICMP or IPPROTO_ICMPV6 protocol, and then making a connect system call after a disconnect.

    Published: 2 May 2015
    6.8
    Medium

    CVE-2015-2248

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for requests that create bookmarks via a crafted request to cgi-bin/editBookmark.

    Published: 1 May 2015
    10
    Critical

    CVE-2015-3435

    Last Modified: 12 Apr 2025

    Samsung Security Manager (SSM) before 1.31 allows remote attackers to execute arbitrary code by uploading a file with an HTTP (1) PUT or (2) MOVE request.

    Published: 1 May 2015
    9.3
    Critical

    CVE-2015-3446

    Last Modified: 12 Apr 2025

    The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a crafted plugin configuration file (.cfg).

    Published: 1 May 2015
    5
    Medium

    CVE-2015-3633

    Last Modified: 12 Apr 2025

    Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via vectors related to digital signatures.

    Published: 1 May 2015
    4.3
    Medium

    CVE-2015-3632

    Last Modified: 12 Apr 2025

    Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.

    Published: 1 May 2015
    7.5
    High

    CVE-2015-0532

    Last Modified: 12 Apr 2025

    EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not properly restrict password resets, which allows remote attackers to obtain access via crafted use of the reset process for an arbitrary valid account name, as demonstrated by a privileged account.

    Published: 1 May 2015
    5
    Medium

    CVE-2015-0914

    Last Modified: 12 Apr 2025

    EasyCTF before 1.4 does not validate the session ID, which allows remote attackers to obtain access via a crafted HTTP request.

    Published: 1 May 2015
    5
    Medium

    CVE-2015-0712

    Last Modified: 12 Apr 2025

    The session-manager service in Cisco StarOS 12.0, 12.2(300), 14.0, and 14.0(600) on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and packet loss) via malformed HTTP packets, aka Bug ID CSCud14217.

    Published: 1 May 2015
    3.5
    Low

    CVE-2015-0913

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in EasyCTF before 1.4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 May 2015
    6.5
    Medium

    CVE-2015-0912

    Last Modified: 12 Apr 2025

    EasyCTF before 1.4 allows remote authenticated users to write executable content to files via unspecified vectors.

    Published: 1 May 2015
    9.8
    Critical

    CVE-2014-8361

    Last Modified: 22 Apr 2026

    The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

    Published: 1 May 2015
    2.6
    Low

    CVE-2015-3455

    Last Modified: 12 Apr 2025

    Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.

    Published: 1 May 2015
    3.5
    Low

    CVE-2015-3988

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate.

    Published: 1 May 2015
    7.5
    High

    CVE-2015-3146

    Last Modified: 12 Apr 2025

    The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted SSH packet.

    Published: 30 Apr 2015
    4.3
    Medium

    CVE-2015-3622

    Last Modified: 12 Apr 2025

    The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.

    Published: 30 Apr 2015
    10
    Critical

    CVE-2015-3459

    Last Modified: 12 Apr 2025

    The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify the pump configuration via unspecified commands.

    Published: 29 Apr 2015
    6.5
    Medium

    CVE-2015-1397

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary SQL commands via the popularity[field_expr] parameter when the popularity[from] or popularity[to] parameter is set.

    Published: 29 Apr 2015
    6.5
    Medium

    CVE-2015-1398

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote authenticated users to include and execute certain PHP files via (1) .. (dot dot) sequences in the PATH_INFO to index.php or (2) vectors involving a block value in the ___directive parameter to the Cms_Wysiwyg controller in the Adminhtml module, related to the blockDirective function and the auto loading mechanism. NOTE: vector 2 might not cross privilege boundaries, since administrators might already have the privileges to execute code and upload files.

    Published: 29 Apr 2015
    6.5
    Medium

    CVE-2015-1399

    Last Modified: 12 Apr 2025

    PHP remote file inclusion vulnerability in the fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allows remote administrators to execute arbitrary PHP code via a URL in unspecified vectors involving the setScriptPath function. NOTE: it is not clear whether this issue crosses privilege boundaries, since administrators might already have privileges to include arbitrary files.

    Published: 29 Apr 2015
    5
    Medium

    CVE-2015-3457

    Last Modified: 12 Apr 2025

    Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.

    Published: 29 Apr 2015
    6.5
    Medium

    CVE-2015-3458

    Last Modified: 12 Apr 2025

    The fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 does not restrict the stream wrapper used in a template path, which allows remote administrators to include and execute arbitrary PHP files via the phar:// stream wrapper, related to the setScriptPath function. NOTE: it is not clear whether this issue crosses privilege boundaries, since administrators might already have privileges to include arbitrary files.

    Published: 29 Apr 2015
    6.8
    Medium

    CVE-2015-1321

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage.

    Published: 29 Apr 2015
    5
    Medium

    CVE-2015-3026

    Last Modified: 12 Apr 2025

    Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as demonstrated by a request to "admin/killsource?mount=/test.ogg."

    Published: 29 Apr 2015
    4.3
    Medium

    CVE-2015-3447

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) searchSpoof or (2) searchSpoofIpDet parameter.

    Published: 29 Apr 2015
    4.6
    Medium

    CVE-2015-1322

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Ubuntu network-manager package for Ubuntu (vivid) before 0.9.10.0-4ubuntu15.1, Ubuntu 14.10 before 0.9.8.8-0ubuntu28.1, and Ubuntu 14.04 LTS before 0.9.8.8-0ubuntu7.1 allows local users to change the modem device configuration or read arbitrary files via a .. (dot dot) in the file name in a request to read modem device contexts (com.canonical.NMOfono.ReadImsiContexts).

    Published: 29 Apr 2015
    6.1
    Medium

    CVE-2015-0710

    Last Modified: 12 Apr 2025

    The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3.10S allows remote attackers to cause a denial of service (device reload) via a series of packets that are considered oversized and trigger improper fragmentation handling, aka Bug IDs CSCup37676 and CSCup30335.

    Published: 29 Apr 2015
    5
    Medium

    CVE-2015-0711

    Last Modified: 12 Apr 2025

    The hamgr service in the IPv6 Proxy Mobile (PM) implementation in Cisco StarOS 18.1.0.59776 on ASR 5000 devices allows remote attackers to cause a denial of service (service reload and call-processing outage) via malformed PM packets, aka Bug ID CSCut94711.

    Published: 29 Apr 2015
    6.1
    Medium

    CVE-2015-0708

    Last Modified: 12 Apr 2025

    Cisco IOS 15.4S, 15.4SN, and 15.5S and IOS XE 3.13S and 3.14S allow remote attackers to cause a denial of service (device crash) by including an IA_NA option in a DHCPv6 Solicit message on the local network, aka Bug ID CSCur29956.

    Published: 29 Apr 2015
    6.8
    Medium

    CVE-2015-0709

    Last Modified: 12 Apr 2025

    Cisco IOS 15.5S and IOS XE allow remote authenticated users to cause a denial of service (device crash) by leveraging knowledge of the RADIUS secret and sending crafted RADIUS packets, aka Bug ID CSCur21348.

    Published: 29 Apr 2015
    7.8
    High

    CVE-2015-3159

    Last Modified: 21 Nov 2024

    The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) does not properly handle the process environment before invoking abrt-action-install-debuginfo, which allows local users to gain privileges.

    Published: 29 Apr 2015
    5.9
    Medium

    CVE-2015-3152

    Last Modified: 12 Apr 2025

    Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.

    Published: 29 Apr 2015