CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-1238

    Last Modified: 12 Apr 2025

    Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.

    Published: 14 Apr 2015
    4.3
    Medium

    CVE-2015-1241

    Last Modified: 12 Apr 2025

    Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.

    Published: 14 Apr 2015
    7.5
    High

    CVE-2015-1242

    Last Modified: 12 Apr 2025

    The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.

    Published: 14 Apr 2015
    5
    Medium

    CVE-2015-1244

    Last Modified: 12 Apr 2025

    The URLRequest::GetHSTSRedirect function in url_request/url_request.cc in Google Chrome before 42.0.2311.90 does not replace the ws scheme with the wss scheme whenever an HSTS Policy is active, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for WebSocket traffic.

    Published: 14 Apr 2015
    5
    Medium

    CVE-2015-1247

    Last Modified: 12 Apr 2025

    The SearchEngineTabHelper::OnPageHasOSDD function in browser/ui/search_engines/search_engine_tab_helper.cc in Google Chrome before 42.0.2311.90 does not prevent use of a file: URL for an OpenSearch descriptor XML document, which might allow remote attackers to obtain sensitive information from local files via a crafted (1) http or (2) https web site.

    Published: 14 Apr 2015
    4.3
    Medium

    CVE-2015-1248

    Last Modified: 12 Apr 2025

    The FileSystem API in Google Chrome before 40.0.2214.91 allows remote attackers to bypass the SafeBrowsing for Executable Files protection mechanism by creating a .exe file in a temporary filesystem and then referencing this file with a filesystem:http: URL.

    Published: 14 Apr 2015
    7.5
    High

    CVE-2015-1249

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 14 Apr 2015
    5.1
    Medium

    CVE-2015-1865

    Last Modified: 6 Aug 2025

    fts.c in coreutils 8.4 allows local users to delete arbitrary files.

    Published: 14 Apr 2015
    9.3
    Critical

    CVE-2015-2846

    Last Modified: 12 Apr 2025

    BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link.

    Published: 13 Apr 2015
    4.3
    Medium

    CVE-2015-2931

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in includes/upload/UploadBase.php in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an application/xml MIME type for a nested SVG with a data: URI.

    Published: 13 Apr 2015
    4.3
    Medium

    CVE-2015-2932

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an animated href XLink element.

    Published: 13 Apr 2015
    4.3
    Medium

    CVE-2015-2933

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Html class in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via a LanguageConverter substitution string when using a language variant.

    Published: 13 Apr 2015
    4.3
    Medium

    CVE-2015-2934

    Last Modified: 12 Apr 2025

    MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 does not properly handle when the Zend interpreter xml_parse function does not expand entities, which allows remote attackers to inject arbitrary web script or HTML via a crafted SVG file.

    Published: 13 Apr 2015
    5
    Medium

    CVE-2015-2935

    Last Modified: 12 Apr 2025

    MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style element in an SVG file, as demonstrated by "@imporT."

    Published: 13 Apr 2015
    7.1
    High

    CVE-2015-2936

    Last Modified: 12 Apr 2025

    MediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows remote attackers to cause a denial of service (CPU consumption) via a long password.

    Published: 13 Apr 2015
    4.3
    Medium

    CVE-2015-2938

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via a custom JavaScript file, which is not properly handled when previewing the file.

    Published: 13 Apr 2015
    4.3
    Medium

    CVE-2015-2939

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Scribunto extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via a function name, which is not properly handled in a Lua error backtrace.

    Published: 13 Apr 2015
    6.8
    Medium

    CVE-2015-2940

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the CheckUser extension for MediaWiki allows remote attackers to hijack the authentication of certain users for requests that retrieve sensitive user information via unspecified vectors.

    Published: 13 Apr 2015
    4.3
    Medium

    CVE-2015-2941

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM, allows remote attackers to inject arbitrary web script or HTML via an invalid parameter in a wddx format request to api.php, which is not properly handled in an error message, related to unsafe calls to wddx_serialize_value.

    Published: 13 Apr 2015
    7.1
    High

    CVE-2015-2942

    Last Modified: 12 Apr 2025

    MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity references in an (1) SVG file or (2) XMP metadata in a PDF file, aka a "billion laughs attack," a different vulnerability than CVE-2015-2937.

    Published: 13 Apr 2015
    7.1
    High

    CVE-2015-2937

    Last Modified: 12 Apr 2025

    MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM or Zend PHP, allows remote attackers to cause a denial of service ("quadratic blowup" and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, a different vulnerability than CVE-2015-2942.

    Published: 13 Apr 2015
    4.3
    Medium

    CVE-2014-9714

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Machine) before 3.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted string to the wddx_serialize_value function.

    Published: 13 Apr 2015
    4.3
    Medium

    CVE-2015-0840

    Last Modified: 12 Apr 2025

    The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).

    Published: 13 Apr 2015
    8.3
    High

    CVE-2015-0675

    Last Modified: 12 Apr 2025

    The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(6), 9.2 before 9.2(3.3), and 9.3 before 9.3(3) does not properly validate failover communication messages, which allows remote attackers to reconfigure an ASA device, and consequently obtain administrative control, by sending crafted UDP packets over the local network to the failover interface, aka Bug ID CSCur21069.

    Published: 13 Apr 2015
    7.8
    High

    CVE-2015-0677

    Last Modified: 12 Apr 2025

    The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before 8.6(1.17), 9.0 before 9.0(4.33), 9.1 before 9.1(6), 9.2 before 9.2(3.4), and 9.3 before 9.3(3), when Clientless SSL VPN, AnyConnect SSL VPN, or AnyConnect IKEv2 VPN is used, allows remote attackers to cause a denial of service (VPN outage or device reload) via a crafted XML document, aka Bug ID CSCus95290.

    Published: 13 Apr 2015
    7.1
    High

    CVE-2015-0676

    Last Modified: 12 Apr 2025

    The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2 before 8.2(5.57), 8.3 before 8.3(2.44), 8.4 before 8.4(7.28), 8.5 before 8.5(1.24), 8.6 before 8.6(1.17), 8.7 before 8.7(1.16), 9.0 before 9.0(4.33), 9.1 before 9.1(6.1), 9.2 before 9.2(3.4), and 9.3 before 9.3(3) allows man-in-the-middle attackers to cause a denial of service (memory consumption or device outage) by triggering outbound DNS queries and then sending crafted responses to these queries, aka Bug ID CSCuq77655.

    Published: 13 Apr 2015
    7.5
    High

    CVE-2015-5621

    Last Modified: 4 Dec 2025

    The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

    Published: 13 Apr 2015
    4.3
    Medium

    CVE-2015-3310

    Last Modified: 12 Apr 2025

    Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.

    Published: 13 Apr 2015
    4.9
    Medium

    CVE-2015-6526

    Last Modified: 12 Apr 2025

    The perf_callchain_user_64 function in arch/powerpc/perf/callchain.c in the Linux kernel before 4.0.2 on ppc64 platforms allows local users to cause a denial of service (infinite loop) via a deep 64-bit userspace backtrace.

    Published: 13 Apr 2015
    5
    Medium

    CVE-2015-0694

    Last Modified: 12 Apr 2025

    Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have been allowed, aka Bug ID CSCur28806.

    Published: 11 Apr 2015
    7.8
    High

    CVE-2015-0678

    Last Modified: 12 Apr 2025

    The virtualization layer in Cisco ASA FirePOWER Software before 5.3.1.2 and 5.4.x before 5.4.0.1 and ASA Context-Aware (CX) Software before 9.3.2.1-9 allows remote attackers to cause a denial of service (device reload) by rapidly sending crafted packets to the management interface, aka Bug IDs CSCus11007 and CSCun56954.

    Published: 11 Apr 2015
    7.2
    High

    CVE-2015-0692

    Last Modified: 12 Apr 2025

    Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via crafted serialized objects, aka Bug ID CSCut39230.

    Published: 11 Apr 2015
    Unknown

    CVE-2013-6151

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6153

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6160

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6161

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6144

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6145

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6146

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6147

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6148

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6149

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6150

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6152

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6155

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6156

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6158

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6154

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6157

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015
    Unknown

    CVE-2013-6159

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 10 Apr 2015