CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2015-0994

    Last Modified: 12 Apr 2025

    Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by using different session ID values in a series of HTTP requests.

    Published: 3 Apr 2015
    5
    Medium

    CVE-2015-0995

    Last Modified: 12 Apr 2025

    Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to obtain access via a brute-force attack.

    Published: 3 Apr 2015
    6.5
    Medium

    CVE-2015-0682

    Last Modified: 12 Apr 2025

    Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka Bug ID CSCup90168.

    Published: 3 Apr 2015
    7.5
    High

    CVE-2015-0903

    Last Modified: 12 Apr 2025

    Buffer overflow in Saitoh Kikaku Maruo Editor 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted .hmbook file.

    Published: 3 Apr 2015
    2.1
    Low

    CVE-2015-0992

    Last Modified: 12 Apr 2025

    Inductive Automation Ignition 7.7.2 stores cleartext OPC Server credentials, which allows local users to obtain sensitive information via unspecified vectors.

    Published: 3 Apr 2015
    6.8
    Medium

    CVE-2014-5400

    Last Modified: 3 Nov 2025

    The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file.

    Published: 3 Apr 2015
    4.4
    Medium

    CVE-2014-8390

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malformed disturbance-recording data in a (1) CFG or (2) DAT file.

    Published: 3 Apr 2015
    4
    Medium

    CVE-2015-0683

    Last Modified: 12 Apr 2025

    Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to obtain sensitive information via a file-inclusion attack, aka Bug ID CSCup94744.

    Published: 3 Apr 2015
    6.5
    Medium

    CVE-2015-0684

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq52515.

    Published: 3 Apr 2015
    7.8
    High

    CVE-2015-0685

    Last Modified: 12 Apr 2025

    Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers to cause a denial of service (device hang) via crafted IP packets, aka Bug ID CSCub31873.

    Published: 3 Apr 2015
    6.3
    Medium

    CVE-2015-0686

    Last Modified: 12 Apr 2025

    The SNMP implementation in Cisco NX-OS 6.1(2)I2(3) on Nexus 9000 devices, when a Reset High Availability (HA) policy is configured, allows remote authenticated users to cause a denial of service (device reload) via unspecified vectors, aka Bug ID CSCuq92240.

    Published: 3 Apr 2015
    6.3
    Medium

    CVE-2015-0687

    Last Modified: 12 Apr 2025

    The SNMP implementation in Cisco IOS 15.1(2)SG4 on Catalyst 4500 devices, when single-switch Virtual Switching System (VSS) is configured, allows remote authenticated users to cause a denial of service (device crash) by performing SNMP polling, aka Bug ID CSCuq04574.

    Published: 3 Apr 2015
    6.9
    Medium

    CVE-2015-2925

    Last Modified: 12 Apr 2025

    The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a "double-chroot attack."

    Published: 3 Apr 2015
    4.3
    Medium

    CVE-2015-0799

    Last Modified: 12 Apr 2025

    The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

    Published: 3 Apr 2015
    7.5
    High

    CVE-2015-8855

    Last Modified: 20 Apr 2025

    The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

    Published: 3 Apr 2015
    3.3
    Low

    CVE-2015-2924

    Last Modified: 12 Apr 2025

    The receive_ra function in rdisc/nm-lndp-rdisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in NetworkManager 1.x allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message, a similar issue to CVE-2015-2922.

    Published: 2 Apr 2015
    7.5
    High

    CVE-2015-1233

    Last Modified: 12 Apr 2025

    Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 1 Apr 2015
    6.8
    Medium

    CVE-2015-1234

    Last Modified: 12 Apr 2025

    Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact by manipulating OpenGL ES commands.

    Published: 1 Apr 2015
    5
    Medium

    CVE-2015-2811

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2111939.

    Published: 1 Apr 2015
    5
    Medium

    CVE-2015-2812

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2093966.

    Published: 1 Apr 2015
    5
    Medium

    CVE-2015-2813

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125358.

    Published: 1 Apr 2015
    6.4
    Medium

    CVE-2015-2814

    Last Modified: 12 Apr 2025

    SAP EMR Unwired (com.sap.mobile.healthcare.emr.v2) and Clinical Task Tracker (com.sap.mobile.healthcare.ctt) does not properly restrict access, which allows remote attackers to change the backendurl, clientid, ssourl, and infopageurl settings via unspecified vectors, aka SAP Security Note 2117079.

    Published: 1 Apr 2015
    6.5
    Medium

    CVE-2015-2815

    Last Modified: 12 Apr 2025

    Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (7400.12.21.30308) allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via unspecified vectors, aka SAP Security Note 2063369.

    Published: 1 Apr 2015
    7.5
    High

    CVE-2015-2816

    Last Modified: 12 Apr 2025

    The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote attackers to have unspecified impact via a crafted request, aka SAP Security Note 2134905.

    Published: 1 Apr 2015
    5
    Medium

    CVE-2015-2818

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125513.

    Published: 1 Apr 2015
    6.5
    Medium

    CVE-2015-2821

    Last Modified: 12 Apr 2025

    TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other editors via unspecified vectors.

    Published: 1 Apr 2015
    5
    Medium

    CVE-2015-2817

    Last Modified: 12 Apr 2025

    The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768.

    Published: 1 Apr 2015
    4.3
    Medium

    CVE-2015-2294

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the WebGUI in pfSense before 2.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) zone parameter to status_captiveportal.php; (2) if or (3) dragtable parameter to firewall_rules.php; (4) queue parameter in an add action to firewall_shaper.php; (5) id parameter in an edit action to services_unbound_acls.php; or (6) filterlogentries_time, (7) filterlogentries_sourceipaddress, (8) filterlogentries_sourceport, (9) filterlogentries_destinationipaddress, (10) filterlogentries_interfaces, (11) filterlogentries_destinationport, (12) filterlogentries_protocolflags, or (13) filterlogentries_qty parameter to diag_logs_filter.php.

    Published: 1 Apr 2015
    4
    Medium

    CVE-2014-9713

    Last Modified: 12 Apr 2025

    The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.

    Published: 1 Apr 2015
    5
    Medium

    CVE-2015-2819

    Last Modified: 12 Apr 2025

    SAP Sybase SQL Anywhere 11 and 16 allows remote attackers to cause a denial of service (crash) via a crafted request, aka SAP Security Note 2108161.

    Published: 1 Apr 2015
    5
    Medium

    CVE-2015-2820

    Last Modified: 12 Apr 2025

    Buffer overflow in XcListener in SAP Afaria 7.0.6001.5 allows remote attackers to cause a denial of service (process termination) via a crafted request, aka SAP Security Note 2132584.

    Published: 1 Apr 2015
    6.8
    Medium

    CVE-2015-2755

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) lat (Latitude), (2) long (Longitude), (3) map_width, (4) map_height, or (5) zoom (Map Zoom) parameter in the ab_map_options page to wp-admin/admin.php.

    Published: 1 Apr 2015
    5
    Medium

    CVE-2012-2808

    Last Modified: 12 Apr 2025

    The PRNG implementation in the DNS resolver in Bionic in Android before 4.1.1 incorrectly uses time and PID information during the generation of random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2015-0800.

    Published: 1 Apr 2015
    5
    Medium

    CVE-2015-0800

    Last Modified: 12 Apr 2025

    The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2012-2808.

    Published: 1 Apr 2015
    4.3
    Medium

    CVE-2015-0810

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript code that interacts with an IMG element.

    Published: 1 Apr 2015
    5
    Medium

    CVE-2015-2809

    Last Modified: 12 Apr 2025

    The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets to the Avahi component.

    Published: 1 Apr 2015
    5
    Medium

    CVE-2015-1892

    Last Modified: 12 Apr 2025

    The Multicast DNS (mDNS) responder in IBM Security Access Manager for Web 7.x before 7.0.0 FP12 and 8.x before 8.0.1 FP1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets.

    Published: 1 Apr 2015
    1.9
    Low

    CVE-2015-2830

    Last Modified: 12 Apr 2025

    arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the (1) fork or (2) close system call, as demonstrated by an attack against seccomp before 3.16.

    Published: 1 Apr 2015
    7.5
    High

    CVE-2015-0225

    Last Modified: 12 Apr 2025

    The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request.

    Published: 1 Apr 2015
    4
    Medium

    CVE-2015-2684

    Last Modified: 12 Apr 2025

    Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2014-2027

    Last Modified: 12 Apr 2025

    eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary files, and possibly execute arbitrary code via the (1) addr_fields or (2) trans parameter to addressbook/csv_import.php, (3) cal_fields or (4) trans parameter to calendar/csv_import.php, (5) info_fields or (6) trans parameter to csv_import.php in (a) projectmanager/ or (b) infolog/, or (7) processed parameter to preferences/inc/class.uiaclprefs.inc.php.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2014-9706

    Last Modified: 12 Apr 2025

    The build_index_from_tree function in index.py in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a commit with a directory path starting with .git/, which is not properly handled when checking out a working tree.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2014-9707

    Last Modified: 12 Apr 2025

    EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-0838

    Last Modified: 12 Apr 2025

    Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary code via a crafted pack file.

    Published: 31 Mar 2015
    6.4
    Medium

    CVE-2015-2106

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27, 3 before 1.82, and 4 before 2.10 allows remote attackers to bypass intended access restrictions or cause a denial of service via unknown vectors.

    Published: 31 Mar 2015
    10
    Critical

    CVE-2014-7876

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27 and 4 before 2.03 and iLO Chassis Management (CM) firmware before 1.30 allows remote attackers to gain privileges, execute arbitrary code, or cause a denial of service via unknown vectors.

    Published: 31 Mar 2015
    4.3
    Medium

    CVE-2015-0900

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in schedule.cgi in Nishishi Factory Fumy Teacher's Schedule Board 1.10 through 2.21 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 31 Mar 2015
    4.3
    Medium

    CVE-2015-0901

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the duwasai flashy theme 1.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Mar 2015
    3.5
    Low

    CVE-2015-2108

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Powershell Operations in HP Operations Orchestration 9.x and 10.x allows remote authenticated users to obtain sensitive information via unknown vectors.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-2109

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Operations Orchestration 10.x allows remote attackers to bypass authentication, and obtain sensitive information or modify data, via unknown vectors.

    Published: 31 Mar 2015