CVE Feed

    Dashboard / CVE

    5.8
    Medium

    CVE-2015-3371

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3372

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.

    Published: 21 Apr 2015
    5
    Medium

    CVE-2015-3373

    Last Modified: 12 Apr 2025

    The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3376

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Quizzler module before 7-x.1.16 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.

    Published: 21 Apr 2015
    7.5
    High

    CVE-2014-5370

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows remote attackers to read or possibly delete arbitrary files via a .. (dot dot) in the QUERY_STRING to cfchart.cfchart.

    Published: 21 Apr 2015
    7.5
    High

    CVE-2015-2825

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the path parameter.

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2014-5361

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Landesk Management Suite 9.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) start, (2) stop, or (3) restart services via a request to remote/serverServices.aspx.

    Published: 21 Apr 2015
    7.8
    High

    CVE-2015-1701

    Last Modified: 22 Apr 2026

    Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."

    Published: 21 Apr 2015
    9
    Critical

    CVE-2015-0702

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated users to execute arbitrary code by using the languageShortName parameter to upload a file that provides shell access, aka Bug ID CSCus95712.

    Published: 21 Apr 2015
    5.5
    Medium

    CVE-2014-8171

    Last Modified: 21 Nov 2024

    The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.

    Published: 21 Apr 2015
    4.3
    Medium

    CVE-2015-0703

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the administrative web interface in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCus95857.

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2015-1781

    Last Modified: 12 Apr 2025

    Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer.

    Published: 21 Apr 2015
    6.2
    Medium

    CVE-2015-3339

    Last Modified: 12 Apr 2025

    Race condition in the prepare_binprm function in fs/exec.c in the Linux kernel before 3.19.6 allows local users to gain privileges by executing a setuid program at a time instant when a chown to root is in progress, and the ownership is changed but the setuid bit is not yet stripped.

    Published: 20 Apr 2015
    2.9
    Low

    CVE-2015-3340

    Last Modified: 12 Apr 2025

    Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.

    Published: 20 Apr 2015
    6.8
    Medium

    CVE-2015-2706

    Last Modified: 12 Apr 2025

    Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization.

    Published: 20 Apr 2015
    7.5
    High

    CVE-2015-3333

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google V8 before 4.2.77.14, as used in Google Chrome before 42.0.2311.90, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 19 Apr 2015
    4.3
    Medium

    CVE-2015-3334

    Last Modified: 12 Apr 2025

    browser/ui/website_settings/website_settings.cc in Google Chrome before 42.0.2311.90 does not always display "Media: Allowed by you" in a Permissions table after the user has granted camera permission to a web site, which might make it easier for user-assisted remote attackers to obtain sensitive video data from a device's physical environment via a crafted web site that turns on the camera at a time when the user believes that camera access is prohibited.

    Published: 19 Apr 2015
    7.5
    High

    CVE-2015-3335

    Last Modified: 12 Apr 2025

    The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandbox_linux/nacl_sandbox_linux.cc in Google Chrome before 42.0.2311.90 does not have RLIMIT_AS and RLIMIT_DATA limits for Native Client (aka NaCl) processes, which might make it easier for remote attackers to conduct row-hammer attacks or have unspecified other impact by leveraging the ability to run a crafted program in the NaCl sandbox.

    Published: 19 Apr 2015
    4.3
    Medium

    CVE-2015-3336

    Last Modified: 12 Apr 2025

    Google Chrome before 42.0.2311.90 does not always ask the user before proceeding with CONTENT_SETTINGS_TYPE_FULLSCREEN and CONTENT_SETTINGS_TYPE_MOUSELOCK changes, which allows user-assisted remote attackers to cause a denial of service (UI disruption) by constructing a crafted HTML document containing JavaScript code with requestFullScreen and requestPointerLock calls, and arranging for the user to access this document with a file: URL.

    Published: 19 Apr 2015
    9.8
    Critical

    CVE-2015-8710

    Last Modified: 12 Apr 2025

    The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed HTML comment.

    Published: 19 Apr 2015
    4.3
    Medium

    CVE-2015-0967

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SearchBlox before 8.2 allow remote attackers to inject arbitrary web script or HTML via (1) the search field in plugin/index.html or (2) the title field in the Create Featured Result form in admin/main.jsp.

    Published: 18 Apr 2015
    7.5
    High

    CVE-2015-0968

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in admin/uploadImage.html in SearchBlox before 8.2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension and the image/jpeg content type, a different vulnerability than CVE-2013-3590.

    Published: 18 Apr 2015
    5
    Medium

    CVE-2015-0969

    Last Modified: 12 Apr 2025

    SearchBlox before 8.2 allows remote attackers to obtain sensitive information via a pretty=true action to the _cluster/health URI.

    Published: 18 Apr 2015
    8.8
    High

    CVE-2015-0970

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in SearchBlox before 8.2 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 18 Apr 2015
    7.5
    High

    CVE-2015-3035

    Last Modified: 21 Apr 2026

    Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.

    Published: 17 Apr 2015
    7.2
    High

    CVE-2015-1318

    Last Modified: 3 Nov 2025

    The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).

    Published: 17 Apr 2015
    7.5
    High

    CVE-2015-0845

    Last Modified: 12 Apr 2025

    Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates.

    Published: 17 Apr 2015
    4.3
    Medium

    CVE-2015-0937

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Apr 2015
    7.8
    High

    CVE-2015-0695

    Last Modified: 12 Apr 2025

    Cisco IOS XR 4.3.4 through 5.3.0 on ASR 9000 devices, when uRPF, PBR, QoS, or an ACL is configured, does not properly handle bridge-group virtual interface (BVI) traffic, which allows remote attackers to cause a denial of service (chip and card hangs and reloads) by triggering use of a BVI interface for IPv4 packets, aka Bug ID CSCur62957.

    Published: 17 Apr 2015
    5
    Medium

    CVE-2015-0938

    Last Modified: 12 Apr 2025

    search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attackers to bypass intended access restrictions, and list or read arbitrary documents, by providing matching keywords in conjunction with a crafted parameter.

    Published: 17 Apr 2015
    9.3
    Critical

    CVE-2015-0691

    Last Modified: 12 Apr 2025

    A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a crafted web site, aka Bug ID CSCup83001.

    Published: 17 Apr 2015
    7.2
    High

    CVE-2015-0530

    Last Modified: 12 Apr 2025

    Buffer overflow in an unspecified function in nsr_render_log in EMC NetWorker before 8.0.4.3, 8.1.x before 8.1.2.6, and 8.2.x before 8.2.1.2 allows local users to gain privileges via unknown vectors.

    Published: 17 Apr 2015
    6.8
    Medium

    CVE-2015-0700

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Dashboard page in the monitoring-and-report section in Cisco Secure Access Control Server Solution Engine before 5.5(0.46.5) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj62924.

    Published: 17 Apr 2015
    7.8
    High

    CVE-2015-1869

    Last Modified: 21 Nov 2024

    The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on a var_log_messages file.

    Published: 17 Apr 2015
    6.5
    Medium

    CVE-2015-3147

    Last Modified: 21 Nov 2024

    daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.

    Published: 17 Apr 2015
    5.5
    Medium

    CVE-2015-1870

    Last Modified: 20 Apr 2025

    The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.

    Published: 17 Apr 2015
    4.7
    Medium

    CVE-2015-3142

    Last Modified: 20 Apr 2025

    The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.

    Published: 17 Apr 2015
    5
    Medium

    CVE-2015-3323

    Last Modified: 12 Apr 2025

    The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface crash) via a malformed HTTP request during authentication.

    Published: 16 Apr 2015
    3.3
    Low

    CVE-2013-4866

    Last Modified: 12 Apr 2025

    The LIXIL Corporation My SATIS Genius Toilet application for Android has a hardcoded Bluetooth PIN, which allows physically proximate attackers to trigger physical resource consumption (water or heat) or user discomfort.

    Published: 16 Apr 2015
    2.1
    Low

    CVE-2015-3320

    Last Modified: 12 Apr 2025

    Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-3324

    Last Modified: 12 Apr 2025

    The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers.

    Published: 16 Apr 2015
    2.1
    Low

    CVE-2015-1314

    Last Modified: 12 Apr 2025

    The USAA Mobile Banking application before 7.10.1 for Android displays the most recently-used screen before prompting the user for login, which might allow physically proximate users to obtain banking account numbers and balances.

    Published: 16 Apr 2015
    5
    Medium

    CVE-2015-3322

    Last Modified: 12 Apr 2025

    Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors.

    Published: 16 Apr 2015
    3.5
    Low

    CVE-2015-0451

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 3.0-04 allows remote authenticated users to affect confidentiality via vectors related to OpenSSO Web Agents.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-0452

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM Server for SPARC component in Oracle Sun Systems Products Suite 3.1 and 3.2 allows remote attackers to affect confidentiality via unknown vectors related to Ldom Manager.

    Published: 16 Apr 2015
    3.3
    Low

    CVE-2015-0453

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote attackers to affect confidentiality via vectors related to PORTAL.

    Published: 16 Apr 2015
    6.8
    Medium

    CVE-2015-0455

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the XDB - XML Database component in Oracle Database Server 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-0456

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.8.0 allows remote attackers to affect integrity via unknown vectors related to Portlet Services.

    Published: 16 Apr 2015
    7.5
    High

    CVE-2015-0495

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce Platform 3.x and 11.x allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Workbench.

    Published: 16 Apr 2015
    2.1
    Low

    CVE-2015-2574

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality via unknown vectors related to Text Utilities.

    Published: 16 Apr 2015