CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2014-9209

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platform before 2.71.00 and FactoryTalk View Studio 8.00.00 and earlier allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 31 Mar 2015
    10
    Critical

    CVE-2015-0984

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O, XL1000C100 104 I/O, XL1000C500 300 I/O, XL1000C1000 600 I/O, XL1000C50U 52 I/O UUKL, XL1000C100U 104 I/O UUKL, XL1000C500U 300 I/O UUKL, and XL1000C1000U 600 I/O UUKL controllers before 2.04.01 allows remote attackers to read files under the web root, and consequently obtain administrative login access, via a crafted pathname.

    Published: 31 Mar 2015
    6.8
    Medium

    CVE-2015-0985

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to hijack the authentication of admins for requests that modify the default user's password via a GET request.

    Published: 31 Mar 2015
    9.1
    Critical

    CVE-2017-6519

    Last Modified: 3 Dec 2025

    avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (traffic amplification) and may cause information leakage by obtaining potentially sensitive information from the responding device via port-5353 UDP packets. NOTE: this may overlap CVE-2015-2809.

    Published: 31 Mar 2015
    5
    Medium

    CVE-2015-0816

    Last Modified: 25 Nov 2025

    Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-0815

    Last Modified: 25 Nov 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 31 Mar 2015
    5.1
    Medium

    CVE-2015-0813

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-0801

    Last Modified: 25 Nov 2025

    Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.

    Published: 31 Mar 2015
    5
    Medium

    CVE-2015-0802

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of access to restricted internal methods.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-0806

    Last Modified: 12 Apr 2025

    The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors that trigger rendering of 2D graphics content.

    Published: 31 Mar 2015
    5
    Medium

    CVE-2014-9708

    Last Modified: 12 Apr 2025

    Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".

    Published: 31 Mar 2015
    7.8
    High

    CVE-2015-0202

    Last Modified: 12 Apr 2025

    The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.

    Published: 31 Mar 2015
    5
    Medium

    CVE-2015-0248

    Last Modified: 12 Apr 2025

    The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evaluated revision numbers.

    Published: 31 Mar 2015
    4
    Medium

    CVE-2015-0251

    Last Modified: 12 Apr 2025

    The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-0803

    Last Modified: 12 Apr 2025

    The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document.

    Published: 31 Mar 2015
    6.8
    Medium

    CVE-2015-0807

    Last Modified: 12 Apr 2025

    The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site, a similar issue to CVE-2014-8638.

    Published: 31 Mar 2015
    5
    Medium

    CVE-2015-0808

    Last Modified: 12 Apr 2025

    The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote attackers to cause a denial of service (memory corruption) via unspecified vectors.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-1867

    Last Modified: 12 Apr 2025

    Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.

    Published: 31 Mar 2015
    4.9
    Medium

    CVE-2015-2756

    Last Modified: 12 Apr 2025

    QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-3414

    Last Modified: 12 Apr 2025

    SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted COLLATE clause, as demonstrated by COLLATE"""""""" at the end of a SELECT statement.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-3415

    Last Modified: 12 Apr 2025

    The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a crafted CHECK clause, as demonstrated by CHECK(0&O>O) in a CREATE TABLE statement.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-0804

    Last Modified: 12 Apr 2025

    The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document containing a SOURCE element.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-0805

    Last Modified: 12 Apr 2025

    The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors that trigger rendering of 2D graphics content.

    Published: 31 Mar 2015
    6.4
    Medium

    CVE-2015-0811

    Last Modified: 12 Apr 2025

    The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image that is improperly handled during transformation.

    Published: 31 Mar 2015
    4.3
    Medium

    CVE-2015-0812

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-0814

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 31 Mar 2015
    7.1
    High

    CVE-2015-2751

    Last Modified: 12 Apr 2025

    Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host lock) via unspecified domctl operations.

    Published: 31 Mar 2015
    4.9
    Medium

    CVE-2015-2752

    Last Modified: 12 Apr 2025

    The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).

    Published: 31 Mar 2015
    7.6
    High

    CVE-2015-2775

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.

    Published: 31 Mar 2015
    7.5
    High

    CVE-2015-3416

    Last Modified: 12 Apr 2025

    The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.

    Published: 31 Mar 2015
    4.3
    Medium

    CVE-2015-2790

    Last Modified: 12 Apr 2025

    Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image.

    Published: 30 Mar 2015
    7.5
    High

    CVE-2015-2171

    Last Modified: 12 Apr 2025

    Middleware/SessionCookie.php in Slim before 2.6.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted session data.

    Published: 30 Mar 2015
    6.5
    Medium

    CVE-2015-2172

    Last Modified: 12 Apr 2025

    DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.

    Published: 30 Mar 2015
    4.4
    Medium

    CVE-2015-2789

    Last Modified: 12 Apr 2025

    Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.

    Published: 30 Mar 2015
    6.4
    Medium

    CVE-2015-2791

    Last Modified: 12 Apr 2025

    The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/menus-sync.php.

    Published: 30 Mar 2015
    7.5
    High

    CVE-2015-2792

    Last Modified: 12 Apr 2025

    The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request containing an action POST parameter, an action GET parameter, and a valid nonce for the action GET parameter.

    Published: 30 Mar 2015
    3.7
    Low

    CVE-2015-2808

    Last Modified: 28 May 2026

    The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.

    Published: 30 Mar 2015
    7.5
    High

    CVE-2015-0899

    Last Modified: 12 Apr 2025

    The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.

    Published: 30 Mar 2015
    7.5
    High

    CVE-2014-8119

    Last Modified: 20 Apr 2025

    The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.

    Published: 30 Mar 2015
    5.9
    Medium

    CVE-2015-1855

    Last Modified: 21 Nov 2024

    verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.

    Published: 30 Mar 2015
    7.5
    High

    CVE-2013-7438

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in pbm212030 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PBM image, related to (1) stream line data, which triggers a heap-based buffer overflow, or (2) vectors related to an "internal intermediate heap-based buffer."

    Published: 29 Mar 2015
    5
    Medium

    CVE-2013-7437

    Last Modified: 12 Apr 2025

    Multiple integer overflows in potrace 1.11 allow remote attackers to cause a denial of service (crash) via large dimensions in a BMP image, which triggers a buffer overflow.

    Published: 29 Mar 2015
    10
    Critical

    CVE-2015-2786

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors related to "Group join request notifications sent to wrong group leaders."

    Published: 29 Mar 2015
    2.1
    Low

    CVE-2015-0996

    Last Modified: 12 Apr 2025

    Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive information by discovering this password.

    Published: 29 Mar 2015
    5
    Medium

    CVE-2014-5427

    Last Modified: 12 Apr 2025

    Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request.

    Published: 29 Mar 2015
    10
    Critical

    CVE-2014-5428

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script.

    Published: 29 Mar 2015
    7.2
    High

    CVE-2015-0528

    Last Modified: 12 Apr 2025

    The RPC daemon in EMC Isilon OneFS 6.5.x and 7.0.x before 7.0.2.13, 7.1.0 before 7.1.0.6, 7.1.1 before 7.1.1.2, and 7.2.0 before 7.2.0.1 allows local users to gain privileges by leveraging an ability to modify system files.

    Published: 29 Mar 2015
    5
    Medium

    CVE-2015-0997

    Last Modified: 12 Apr 2025

    Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user interface that lists all valid usernames, which makes it easier for remote attackers to obtain access via a brute-force password-guessing attack.

    Published: 29 Mar 2015
    7.5
    High

    CVE-2014-9205

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMOTIC stable before 8.2.19 and PROMOTIC development before 8.3.2 allows remote attackers to execute arbitrary code by providing a large amount of data.

    Published: 29 Mar 2015
    3.3
    Low

    CVE-2015-0998

    Last Modified: 12 Apr 2025

    Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 transmit cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 29 Mar 2015