CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2015-0999

    Last Modified: 12 Apr 2025

    Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 store cleartext OPC User credentials in a configuration file, which allows local users to obtain sensitive information by reading this file.

    Published: 29 Mar 2015
    4
    Medium

    CVE-2015-1844

    Last Modified: 12 Apr 2025

    Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.

    Published: 29 Mar 2015
    7.9
    High

    CVE-2015-0658

    Last Modified: 12 Apr 2025

    The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.

    Published: 28 Mar 2015
    6.1
    Medium

    CVE-2015-0679

    Last Modified: 12 Apr 2025

    The web-authentication functionality on Cisco Wireless LAN Controller (WLC) devices 7.3(103.8) and 7.4(110.0) allows remote attackers to cause a denial of service (device reload) via a malformed password, aka Bug ID CSCui57980.

    Published: 28 Mar 2015
    4
    Medium

    CVE-2015-0680

    Last Modified: 12 Apr 2025

    Cisco Unified Call Manager (CM) 9.1(2.1000.28) does not properly restrict resource requests, which allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuq44439.

    Published: 28 Mar 2015
    6.5
    Medium

    CVE-2015-2758

    Last Modified: 12 Apr 2025

    The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain sensitive information, modify the database, or possibly have other unspecified impact via a crafted URL.

    Published: 27 Mar 2015
    4.3
    Medium

    CVE-2015-2768

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Websense TRITON AP-EMAIL before 8.0.0 and V-Series 7.7 appliances allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Mar 2015
    7.5
    High

    CVE-2013-2184

    Last Modified: 12 Apr 2025

    Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.

    Published: 27 Mar 2015
    4
    Medium

    CVE-2014-9712

    Last Modified: 12 Apr 2025

    Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 and 7.8.4 before Hotfix 01 allow remote administrators to read arbitrary files and obtain passwords via a crafted path.

    Published: 27 Mar 2015
    4
    Medium

    CVE-2015-2757

    Last Modified: 12 Apr 2025

    The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to cause a denial of service (database lock or license corruption) via unspecified vectors.

    Published: 27 Mar 2015
    6.8
    Medium

    CVE-2015-2769

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 27 Mar 2015
    5
    Medium

    CVE-2015-2766

    Last Modified: 12 Apr 2025

    The Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allows attackers to have unspecified impact via a brute force attack.

    Published: 27 Mar 2015
    10
    Critical

    CVE-2015-2767

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."

    Published: 27 Mar 2015
    2.1
    Low

    CVE-2015-2157

    Last Modified: 12 Apr 2025

    The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.

    Published: 27 Mar 2015
    4.3
    Medium

    CVE-2015-2764

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Websense TRITON AP-DATA before 8.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the DSS (1) Mobile or (2) DLP report catalog.

    Published: 27 Mar 2015
    4.3
    Medium

    CVE-2015-2765

    Last Modified: 12 Apr 2025

    The Email Security Gateway in Websense TRITON AP-EMAIL before 8.0.0 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

    Published: 27 Mar 2015
    6.8
    Medium

    CVE-2015-2759

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allow remote attackers to hijack the authentication of users for requests that (1) obtain sensitive information or (2) modify the database via unspecified vectors.

    Published: 27 Mar 2015
    3.5
    Low

    CVE-2015-2760

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Mar 2015
    4.3
    Medium

    CVE-2015-2761

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Exceptions and Scanning Exceptions Pages in Websense TRITON AP-WEB before 8.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Mar 2015
    5
    Medium

    CVE-2015-2762

    Last Modified: 12 Apr 2025

    Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentication.

    Published: 27 Mar 2015
    10
    Critical

    CVE-2015-2763

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to port 17703.

    Published: 27 Mar 2015
    6.8
    Medium

    CVE-2015-2770

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the command line page in Websense TRITON V-Series appliances before 8.0.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 27 Mar 2015
    5
    Medium

    CVE-2015-2771

    Last Modified: 12 Apr 2025

    The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 27 Mar 2015
    7.5
    High

    CVE-2015-2772

    Last Modified: 12 Apr 2025

    SVM in Websense TRITON V-Series appliances before 8.0.0 allows attackers to upload arbitrary files via unspecified vectors.

    Published: 27 Mar 2015
    5
    Medium

    CVE-2015-2773

    Last Modified: 12 Apr 2025

    SVM in Websense TRITON V-Series appliances before 8.0.0 allows attackers to read arbitrary files via unspecified vectors.

    Published: 27 Mar 2015
    4.3
    Medium

    CVE-2015-1843

    Last Modified: 12 Apr 2025

    The Red Hat docker package before 1.5.0-28, when using the --add-registry option, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic. NOTE: this vulnerability exists because of a CVE-2014-5277 regression.

    Published: 27 Mar 2015
    7.5
    High

    CVE-2015-8860

    Last Modified: 20 Apr 2025

    The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.

    Published: 27 Mar 2015
    5
    Medium

    CVE-2015-2682

    Last Modified: 12 Apr 2025

    Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.

    Published: 26 Mar 2015
    7.5
    High

    CVE-2015-2683

    Last Modified: 12 Apr 2025

    Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX) Servlet, which allows remote attackers to execute arbitrary code via unspecified vectors to servlets/Jmx_dynamic.

    Published: 26 Mar 2015
    5
    Medium

    CVE-2015-2748

    Last Modified: 12 Apr 2025

    Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sensitive information via a direct request to a (1) Web Security incident report or the (2) Explorer configuration (websense.ini) file.

    Published: 26 Mar 2015
    6.5
    Medium

    CVE-2015-2746

    Last Modified: 12 Apr 2025

    The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the "second" parameter of a command, as demonstrated by the Destination parameter in the ping command.

    Published: 26 Mar 2015
    4.3
    Medium

    CVE-2015-2747

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the data loss prevention (DLP) incident Forensics Preview in Websense Triton 7.8.3 and V-Series 7.7 appliances allow remote attackers to inject arbitrary web script or HTML via a crafted (1) email or (2) HTTP request, which triggers a DLP Policy.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0641

    Last Modified: 12 Apr 2025

    Cisco IOS XE 2.x and 3.x before 3.9.0S, 3.10 before 3.10.0S, 3.11 before 3.11.0S, 3.12 before 3.12.0S, 3.13 before 3.13.0S, 3.14 before 3.14.0S, and 3.15 before 3.15.0S allows remote attackers to cause a denial of service (device reload) via crafted IPv6 packets, aka Bug ID CSCub68073.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0650

    Last Modified: 12 Apr 2025

    The Service Discovery Gateway (aka mDNS Gateway) in Cisco IOS 12.2, 12.4, 15.0, 15.1, 15.2, 15.3, and 15.4 and IOS XE 3.9.xS and 3.10.xS before 3.10.4S, 3.11.xS before 3.11.3S, 3.12.xS before 3.12.2S, and 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (device reload) by sending malformed mDNS UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCup70579.

    Published: 26 Mar 2015
    4
    Medium

    CVE-2015-0673

    Last Modified: 12 Apr 2025

    Cisco Mobility Services Engine (MSE) 8.0(110.0) allows remote authenticated users to discover the passwords of arbitrary users by (1) reading log files or (2) using an unspecified GUI feature, aka Bug ID CSCut24792.

    Published: 26 Mar 2015
    9
    Critical

    CVE-2015-0635

    Last Modified: 12 Apr 2025

    The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to spoof Autonomic Networking Registration Authority (ANRA) responses, and consequently bypass intended device and node access restrictions or cause a denial of service (disrupted domain access), via crafted AN messages, aka Bug ID CSCup62191.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0642

    Last Modified: 12 Apr 2025

    Cisco IOS 12.2, 12.4, 15.0, 15.1, 15.2, 15.3, and 15.4 and IOS XE 2.5.x, 2.6.x, 3.1.xS through 3.12.xS before 3.12.3S, 3.2.xE through 3.7.xE before 3.7.1E, 3.3.xSG, 3.4.xSG, and 3.13.xS before 3.13.2S allow remote attackers to cause a denial of service (device reload) by sending malformed IKEv2 packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCum36951.

    Published: 26 Mar 2015
    5
    Medium

    CVE-2015-0672

    Last Modified: 12 Apr 2025

    The DHCPv4 server in Cisco IOS XR 5.2.2 on ASR 9000 devices allows remote attackers to cause a denial of service (service outage) via a flood of crafted DHCP packets, aka Bug ID CSCup67822.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0649

    Last Modified: 12 Apr 2025

    Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun63514.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0640

    Last Modified: 12 Apr 2025

    The high-speed logging (HSL) feature in Cisco IOS XE 2.x and 3.x before 3.10.4S, 3.11 before 3.11.3S, 3.12 before 3.12.1S, 3.13 before 3.13.0S, 3.14 before 3.14.0S, and 3.15 before 3.15.0S allows remote attackers to cause a denial of service (device reload) via large IP packets that require NAT and HSL processing after fragmentation, aka Bug ID CSCuo25741.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0636

    Last Modified: 12 Apr 2025

    The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (disrupted domain access) via spoofed AN messages that reset a finite state machine, aka Bug ID CSCup62293.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0637

    Last Modified: 12 Apr 2025

    The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (device reload) via spoofed AN messages, aka Bug ID CSCup62315.

    Published: 26 Mar 2015
    7.1
    High

    CVE-2015-0638

    Last Modified: 12 Apr 2025

    Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge) via crafted ICMPv4 packets, aka Bug ID CSCsi02145.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0639

    Last Modified: 12 Apr 2025

    The Common Flow Table (CFT) feature in Cisco IOS XE 3.6 and 3.7 before 3.7.1S, 3.8 before 3.8.0S, 3.9 before 3.9.0S, 3.10 before 3.10.0S, 3.11 before 3.11.0S, 3.12 before 3.12.0S, 3.13 before 3.13.0S, 3.14 before 3.14.0S, and 3.15 before 3.15.0S, when MMON or NBAR is enabled, allows remote attackers to cause a denial of service (device reload) via malformed IPv6 packets with IPv4 UDP encapsulation, aka Bug ID CSCua79665.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0643

    Last Modified: 12 Apr 2025

    Cisco IOS 12.2, 12.4, 15.0, 15.1, 15.2, 15.3, and 15.4 and IOS XE 2.5.x, 2.6.x, 3.1.xS through 3.12.xS before 3.12.3S, 3.2.xE through 3.7.xE before 3.7.1E, 3.3.xSG, 3.4.xSG, and 3.13.xS before 3.13.2S allow remote attackers to cause a denial of service (memory consumption and device reload) by sending malformed IKEv2 packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCuo75572.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0644

    Last Modified: 12 Apr 2025

    AppNav in Cisco IOS XE 3.8 through 3.10 before 3.10.3S, 3.11 before 3.11.3S, 3.12 before 3.12.1S, 3.13 before 3.13.0S, 3.14 before 3.14.0S, and 3.15 before 3.15.0S allows remote attackers to execute arbitrary code or cause a denial of service (device reload) via a crafted TCP packet, aka Bug ID CSCuo53622.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0645

    Last Modified: 12 Apr 2025

    The Layer 4 Redirect (L4R) feature in Cisco IOS XE 2.x and 3.x before 3.10.4S, 3.11 before 3.11.3S, 3.12 before 3.12.2S, 3.13 before 3.13.1S, 3.14 before 3.14.0S, and 3.15 before 3.15.0S allows remote attackers to cause a denial of service (device reload) via malformed (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCuq59131.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0646

    Last Modified: 12 Apr 2025

    Memory leak in the TCP input module in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.3.xXO, 3.5.xE, 3.6.xE, 3.8.xS through 3.10.xS before 3.10.5S, and 3.11.xS and 3.12.xS before 3.12.3S allows remote attackers to cause a denial of service (memory consumption or device reload) by sending crafted TCP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCum94811.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0647

    Last Modified: 12 Apr 2025

    Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) UDP packets, aka Bug ID CSCum98371.

    Published: 26 Mar 2015
    7.8
    High

    CVE-2015-0648

    Last Modified: 12 Apr 2025

    Memory leak in Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (memory consumption) via crafted Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun49658.

    Published: 26 Mar 2015