CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2015-2579

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Health Sciences Argus Safety component in Oracle Health Sciences Applications 8.0 allows local users to affect confidentiality via vectors related to BIP Installer.

    Published: 16 Apr 2015
    5
    Medium

    CVE-2015-0440

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Knowledge component in Oracle Right Now Service Cloud 8.2.3.10.1 and 8.4.7.2 allows remote attackers to affect integrity via unknown vectors related to Information Manager Console.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-0447

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via vectors related to Configurator DMZ rules.

    Published: 16 Apr 2015
    7
    High

    CVE-2015-0461

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5 and 11.1.1.7 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Authentication Engine.

    Published: 16 Apr 2015
    4
    Medium

    CVE-2015-0462

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, and 6.3.6 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.

    Published: 16 Apr 2015
    5
    Medium

    CVE-2015-0464

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, and 6.3.6 allows remote attackers to affect confidentiality via unknown vectors related to Security.

    Published: 16 Apr 2015
    6
    Medium

    CVE-2015-0482

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.2.0 and 12.1.3.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to WLS-WebServices.

    Published: 16 Apr 2015
    1.2
    Low

    CVE-2015-0489

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Application Management Pack for Oracle E-Business Suite component in Oracle E-Business Suite AMP 121030 and 121020 allows local users to affect confidentiality via vectors related to EBS Plugin.

    Published: 16 Apr 2015
    4
    Medium

    CVE-2015-0496

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect confidentiality via vectors related to PIA Search Functionality.

    Published: 16 Apr 2015
    2.6
    Low

    CVE-2015-0504

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Error Messages.

    Published: 16 Apr 2015
    6.5
    Medium

    CVE-2015-2570

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Demand Planning component in Oracle Supply Chain Products Suite 11.5.10, 12.0, 12.1, and 12.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Security.

    Published: 16 Apr 2015
    4
    Medium

    CVE-2015-0479

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the XDK and XDB - XML Database component in Oracle Database Server 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect availability via unknown vectors.

    Published: 16 Apr 2015
    5.5
    Medium

    CVE-2015-0476

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the SQL Trace Analyzer component in Oracle Support Tools before 12.1.11 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-0502

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1 and 8.2 allows remote attackers to affect integrity via unknown vectors related to Portal Framework.

    Published: 16 Apr 2015
    7.2
    High

    CVE-2015-0448

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via vectors related to ZFS File system.

    Published: 16 Apr 2015
    5
    Medium

    CVE-2015-0449

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Console.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-0450

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.8.0 allows remote attackers to affect integrity via unknown vectors related to WebCenter Spaces Application.

    Published: 16 Apr 2015
    9
    Critical

    CVE-2015-0457

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-2629.

    Published: 16 Apr 2015
    4
    Medium

    CVE-2015-0463

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, and 6.3.6 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.

    Published: 16 Apr 2015
    4
    Medium

    CVE-2015-0465

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, and 6.3.6 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Infrastructure.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-0466

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Retail Back Office component in Oracle Retail Applications 12.0, 12.0IN, 13.0, 13.1, 13.2, 13.3, 13.4, 14.0, and 14.1 allows remote attackers to affect integrity via unknown vectors.

    Published: 16 Apr 2015
    4.4
    Medium

    CVE-2015-0471

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to libelfsign.

    Published: 16 Apr 2015
    3.5
    Low

    CVE-2015-0472

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology, a different vulnerability than CVE-2015-0487.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-0473

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control MOS 12.1.0.5 and 12.1.0.6 allows remote attackers to affect integrity via unknown vectors related to My Oracle Support Plugin.

    Published: 16 Apr 2015
    1.5
    Low

    CVE-2015-0474

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-0493.

    Published: 16 Apr 2015
    4
    Medium

    CVE-2015-0475

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the JD Edwards EnterpriseOne Technology component in Oracle JD Edwards Products 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web Runtime Security.

    Published: 16 Apr 2015
    4
    Medium

    CVE-2015-0483

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect integrity via unknown vectors.

    Published: 16 Apr 2015
    3.5
    Low

    CVE-2015-0485

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise SCM Strategic Sourcing component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.

    Published: 16 Apr 2015
    4
    Medium

    CVE-2015-0487

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology, a different vulnerability than CVE-2015-0472.

    Published: 16 Apr 2015
    4.9
    Medium

    CVE-2015-0490

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to BAS - Base Component.

    Published: 16 Apr 2015
    1.5
    Low

    CVE-2015-0493

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-0474.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-0494

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Retail Central Office component in Oracle Retail Applications 13.1, 13.2, 13.3, 13.4, 14.0, and 14.1 allows remote attackers to affect integrity via unknown vectors.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-0497

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise Portal Interaction Hub component in Oracle PeopleSoft Products 9.1.00 allows remote attackers to affect integrity via unknown vectors related to Enterprise Portal.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-0509

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Hyperion BI+ component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to Reporting and Analysis.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-0510

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Commerce Platform component in Oracle Commerce Platform 9.4, 10.0, and 10.2 allows remote attackers to affect integrity via vectors related to Dynamo Application Framework - HTML Admin User Interface.

    Published: 16 Apr 2015
    4.3
    Medium

    CVE-2015-2565

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Installed Base component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Create Item Instance.

    Published: 16 Apr 2015
    4.6
    Medium

    CVE-2015-2572

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Hyperion Smart View for Office component in Oracle Hyperion 11.1.2.5.216 and earlier, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.

    Published: 16 Apr 2015
    7.2
    High

    CVE-2015-2577

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Accounting commands.

    Published: 16 Apr 2015
    7.1
    High

    CVE-2015-2578

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.2 allows remote attackers to affect availability via vectors related to Kernel IDMap.

    Published: 16 Apr 2015
    5
    Medium

    CVE-2015-3319

    Last Modified: 12 Apr 2025

    Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

    Published: 16 Apr 2015
    5.8
    Medium

    CVE-2015-2783

    Last Modified: 12 Apr 2025

    ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read and application crash) via a crafted length value in conjunction with crafted serialized data in a phar archive, related to the phar_parse_metadata and phar_parse_pharfile functions.

    Published: 16 Apr 2015
    7.5
    High

    CVE-2015-3308

    Last Modified: 12 Apr 2025

    Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.

    Published: 16 Apr 2015
    9.8
    Critical

    CVE-2015-4600

    Last Modified: 12 Apr 2025

    The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in the (1) SoapClient::__getLastRequest, (2) SoapClient::__getLastResponse, (3) SoapClient::__getLastRequestHeaders, (4) SoapClient::__getLastResponseHeaders, (5) SoapClient::__getCookies, and (6) SoapClient::__setCookie methods.

    Published: 16 Apr 2015
    7.5
    High

    CVE-2015-3329

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) phar, or (3) ZIP archive.

    Published: 16 Apr 2015
    6.5
    Medium

    CVE-2015-3411

    Last Modified: 12 Apr 2025

    PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files.

    Published: 16 Apr 2015
    5.3
    Medium

    CVE-2015-3412

    Last Modified: 12 Apr 2025

    PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls the stream_resolve_include_path function in ext/standard/streamsfuncs.c, as demonstrated by a filename\0.extension attack that bypasses an intended configuration in which client users may read files with only one specific extension.

    Published: 16 Apr 2015
    9.8
    Critical

    CVE-2015-4599

    Last Modified: 12 Apr 2025

    The SoapFault::__toString method in ext/soap/soap.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information, cause a denial of service (application crash), or possibly execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

    Published: 16 Apr 2015
    9.8
    Critical

    CVE-2015-4601

    Last Modified: 12 Apr 2025

    PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in (1) ext/soap/php_encoding.c, (2) ext/soap/php_http.c, and (3) ext/soap/soap.c, a different issue than CVE-2015-4600.

    Published: 16 Apr 2015
    6.8
    Medium

    CVE-2015-3330

    Last Modified: 12 Apr 2025

    The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that result in a "deconfigured interpreter."

    Published: 16 Apr 2015
    7.5
    High

    CVE-2015-4604

    Last Modified: 12 Apr 2025

    The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.

    Published: 16 Apr 2015