CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2015-1108

    Last Modified: 12 Apr 2025

    The Lock Screen component in Apple iOS before 8.3 does not properly enforce the limit on incorrect passcode-authentication attempts, which makes it easier for physically proximate attackers to obtain access by making many passcode guesses.

    Published: 10 Apr 2015
    2.1
    Low

    CVE-2015-1109

    Last Modified: 12 Apr 2025

    NetworkExtension in Apple iOS before 8.3 stores credentials in VPN configuration logs, which makes it easier for physically proximate attackers to obtain sensitive information by reading a log file.

    Published: 10 Apr 2015
    5
    Medium

    CVE-2015-1110

    Last Modified: 12 Apr 2025

    The Podcasts component in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to discover unique identifiers by reading asset-download request data.

    Published: 10 Apr 2015
    1.9
    Low

    CVE-2015-1114

    Last Modified: 12 Apr 2025

    The Sandbox Profiles component in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to discover hardware identifiers via a crafted app.

    Published: 10 Apr 2015
    4.4
    Medium

    CVE-2015-1115

    Last Modified: 12 Apr 2025

    The Telephony component in Apple iOS before 8.3 allows attackers to bypass a sandbox protection mechanism and access unintended telephone capabilities via a crafted app.

    Published: 10 Apr 2015
    6.9
    Medium

    CVE-2015-1117

    Last Modified: 12 Apr 2025

    The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 do not properly perform privilege drops, which makes it easier for attackers to execute code with unintended user or group privileges via a crafted app.

    Published: 10 Apr 2015
    5
    Medium

    CVE-2015-1118

    Last Modified: 12 Apr 2025

    libnetcore in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service (memory corruption and application crash) via a crafted configuration profile.

    Published: 10 Apr 2015
    6.8
    Medium

    CVE-2015-1119

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-SA-2015-04-08-4.

    Published: 10 Apr 2015
    6.8
    Medium

    CVE-2015-1122

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-SA-2015-04-08-4.

    Published: 10 Apr 2015
    6.8
    Medium

    CVE-2015-1123

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.3 and Apple TV before 7.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-3 and APPLE-SA-2015-04-08-4.

    Published: 10 Apr 2015
    6.8
    Medium

    CVE-2015-1124

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-SA-2015-04-08-4.

    Published: 10 Apr 2015
    4.3
    Medium

    CVE-2015-1125

    Last Modified: 12 Apr 2025

    The touch-events implementation in WebKit in Apple iOS before 8.3 allows remote attackers to trigger an association between a tap and an unintended web resource via a crafted web site.

    Published: 10 Apr 2015
    4.3
    Medium

    CVE-2015-1126

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not properly handle the userinfo field in FTP URLs, which allows remote attackers to trigger incorrect resource access via unspecified vectors.

    Published: 10 Apr 2015
    4.3
    Medium

    CVE-2015-1129

    Last Modified: 12 Apr 2025

    Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 does not properly select X.509 client certificates, which makes it easier for remote attackers to track users via a crafted web site.

    Published: 10 Apr 2015
    7.2
    High

    CVE-2015-1131

    Last Modified: 12 Apr 2025

    fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1132, CVE-2015-1133, CVE-2015-1134, and CVE-2015-1135.

    Published: 10 Apr 2015
    7.2
    High

    CVE-2015-1133

    Last Modified: 12 Apr 2025

    fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1134, and CVE-2015-1135.

    Published: 10 Apr 2015
    7.2
    High

    CVE-2015-1134

    Last Modified: 12 Apr 2025

    fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1135.

    Published: 10 Apr 2015
    7.2
    High

    CVE-2015-1135

    Last Modified: 12 Apr 2025

    fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1134.

    Published: 10 Apr 2015
    7.2
    High

    CVE-2015-1143

    Last Modified: 12 Apr 2025

    LaunchServices in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted localized string, related to a "type confusion" issue.

    Published: 10 Apr 2015
    7.2
    High

    CVE-2015-1144

    Last Modified: 12 Apr 2025

    Buffer overflow in the UniformTypeIdentifiers component in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted Uniform Type Identifier.

    Published: 10 Apr 2015
    1.9
    Low

    CVE-2015-1145

    Last Modified: 12 Apr 2025

    The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different vulnerability than CVE-2015-1146.

    Published: 10 Apr 2015
    1.9
    Low

    CVE-2015-1146

    Last Modified: 12 Apr 2025

    The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different vulnerability than CVE-2015-1145.

    Published: 10 Apr 2015
    5
    Medium

    CVE-2015-1147

    Last Modified: 12 Apr 2025

    Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 10 Apr 2015
    5
    Medium

    CVE-2015-1148

    Last Modified: 12 Apr 2025

    Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-dependent attackers to obtain sensitive information by reading this file.

    Published: 10 Apr 2015
    7.5
    High

    CVE-2015-1149

    Last Modified: 12 Apr 2025

    Integer overflow in the simulator in Swift in Apple Xcode before 6.3 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact by triggering an incorrect result of a type conversion.

    Published: 10 Apr 2015
    2.1
    Low

    CVE-2015-1415

    Last Modified: 12 Apr 2025

    The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading the file.

    Published: 10 Apr 2015
    6.8
    Medium

    CVE-2015-2295

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deletefile parameter.

    Published: 10 Apr 2015
    5
    Medium

    CVE-2015-2779

    Last Modified: 12 Apr 2025

    Stack consumption vulnerability in the message splitting functionality in Quassel before 0.12-rc1 allows remote attackers to cause a denial of service (uncontrolled recursion) via a crafted massage.

    Published: 10 Apr 2015
    9.8
    Critical

    CVE-2015-8778

    Last Modified: 12 Apr 2025

    Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access.

    Published: 10 Apr 2015
    7.5
    High

    CVE-2015-4025

    Last Modified: 12 Apr 2025

    PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2) tempnam, (3) rmdir, or (4) readlink. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

    Published: 10 Apr 2015
    2.1
    Low

    CVE-2015-3199

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue in a product. Notes: none.

    Published: 10 Apr 2015
    7.5
    High

    CVE-2015-3405

    Last Modified: 20 Apr 2025

    ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.

    Published: 9 Apr 2015
    5.5
    Medium

    CVE-2015-3028

    Last Modified: 12 Apr 2025

    McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to bypass intended restrictions and change or update configuration settings via crafted parameters.

    Published: 8 Apr 2015
    4
    Medium

    CVE-2015-3029

    Last Modified: 12 Apr 2025

    The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 does not properly restrict access, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 8 Apr 2015
    4
    Medium

    CVE-2015-3030

    Last Modified: 12 Apr 2025

    The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to obtain sensitive configuration information via unspecified vectors.

    Published: 8 Apr 2015
    5.8
    Medium

    CVE-2015-0556

    Last Modified: 12 Apr 2025

    Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.

    Published: 8 Apr 2015
    5.8
    Medium

    CVE-2015-0557

    Last Modified: 12 Apr 2025

    Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.

    Published: 8 Apr 2015
    7.5
    High

    CVE-2015-1317

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents while a RenderProcessHost instance still exists.

    Published: 8 Apr 2015
    7.5
    High

    CVE-2015-2782

    Last Modified: 12 Apr 2025

    Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive.

    Published: 8 Apr 2015
    4.3
    Medium

    CVE-2015-2822

    Last Modified: 12 Apr 2025

    Siemens SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2 and SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2 allow man-in-the-middle attackers to cause a denial of service via crafted packets on TCP port 102.

    Published: 8 Apr 2015
    6.8
    Medium

    CVE-2015-2823

    Last Modified: 12 Apr 2025

    Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Professional before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Basic Panels 1st Generation (WinCC TIA Portal), SIMATIC HMI Mobile Panel 277 (WinCC TIA Portal), SIMATIC HMI Multi Panels (WinCC TIA Portal), and SIMATIC WinCC 7.x before 7.3 Upd4 allow remote attackers to complete authentication by leveraging knowledge of a password hash without knowledge of the associated password.

    Published: 8 Apr 2015
    5
    Medium

    CVE-2015-0798

    Last Modified: 12 Apr 2025

    The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy.

    Published: 8 Apr 2015
    3.5
    Low

    CVE-2015-2827

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in CA Spectrum 9.2.x and 9.3.x before 9.3 H02 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Apr 2015
    9
    Critical

    CVE-2015-2828

    Last Modified: 12 Apr 2025

    CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authenticated users to obtain administrative privileges via crafted object data.

    Published: 8 Apr 2015
    6.8
    Medium

    CVE-2015-0905

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in bBlog allows remote attackers to hijack the authentication of arbitrary users.

    Published: 8 Apr 2015
    4.3
    Medium

    CVE-2015-1773

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in asdoc/templates/index.html in Apache Flex before 4.14.1 allows remote attackers to inject arbitrary web script or HTML by providing a crafted URI to JavaScript code generated by the asdoc component.

    Published: 8 Apr 2015
    7.5
    High

    CVE-2016-4353

    Last Modified: 12 Apr 2025

    ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.

    Published: 8 Apr 2015
    4.9
    Medium

    CVE-2014-9715

    Last Modified: 12 Apr 2025

    include/net/netfilter/nf_conntrack_extend.h in the netfilter subsystem in the Linux kernel before 3.14.5 uses an insufficiently large data type for certain extension data, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via outbound network traffic that triggers extension loading, as demonstrated by configuring a PPTP tunnel in a NAT environment.

    Published: 8 Apr 2015
    7.5
    High

    CVE-2016-4354

    Last Modified: 12 Apr 2025

    ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.

    Published: 8 Apr 2015
    7.5
    High

    CVE-2016-4355

    Last Modified: 12 Apr 2025

    Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.

    Published: 8 Apr 2015