CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2015-0283

    Last Modified: 12 Apr 2025

    The slapi-nis plug-in before 0.54.2 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request for a (1) group with a large number of members or (2) user that belongs to a large number of groups.

    Published: 26 Mar 2015
    10
    Critical

    CVE-2015-1815

    Last Modified: 12 Apr 2025

    The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.

    Published: 26 Mar 2015
    3.7
    Low

    CVE-2015-1841

    Last Modified: 12 Apr 2025

    The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.

    Published: 26 Mar 2015
    10
    Critical

    CVE-2015-2806

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.

    Published: 26 Mar 2015
    4.3
    Medium

    CVE-2014-9711

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Investigative Reports in Websense TRITON AP-WEB before 8.0.0 and Web Security and Filter, Web Security Gateway, and Web Security Gateway Anywhere 7.8.3 before Hotfix 02 and 7.8.4 before Hotfix 01 allow remote attackers to inject arbitrary web script or HTML via the (1) ReportName (Job Name) parameter to the Explorer report scheduler (cgi-bin/WsCgiExplorerSchedule.exe) in the Job Queue or the col parameter to the (2) Names or (3) Anonymous (explorer_wse/explorer_anon.exe) summary report page.

    Published: 25 Mar 2015
    6.8
    Medium

    CVE-2015-2701

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a request to profiles-update/.

    Published: 25 Mar 2015
    3.5
    Low

    CVE-2015-2559

    Last Modified: 12 Apr 2025

    Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as another account and a crafted password reset URL.

    Published: 25 Mar 2015
    4.3
    Medium

    CVE-2015-2702

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Message Log in the Email Security Gateway in Websense TRITON AP-EMAIL before 8.0.0 and V-Series 7.7 appliances allows remote attackers to inject arbitrary web script or HTML via the sender address in an email.

    Published: 25 Mar 2015
    4.3
    Medium

    CVE-2015-2703

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Websense TRITON AP-WEB before 8.0.0 and V-Series 7.7 appliances allow remote attackers to inject arbitrary web script or HTML via the (1) ws-userip in the ws-encdata parameter to cve-bin/moreBlockInfo.cgi in the Data Security block page or (2) admin_msg parameter to configure/ssl_ui/eva-config/client-cert-import_wsoem.html in the Content Gateway, which is not properly handled in an error message.

    Published: 25 Mar 2015
    1.2
    Low

    CVE-2014-6134

    Last Modified: 12 Apr 2025

    IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, retains cleartext server passwords in process memory throughout the installation procedure, which might allow local users to obtain sensitive information by leveraging access to the installation account.

    Published: 25 Mar 2015
    1.9
    Low

    CVE-2014-8923

    Last Modified: 12 Apr 2025

    The (1) IBM Tivoli Identity Manager Active Directory adapter before 5.1.24 and (2) IBM Security Identity Manager Active Directory adapter before 6.0.14 for IBM Security Identity Manager on Windows, when certain log and trace levels are configured, store the cleartext administrator password in a log file, which allows local users to obtain sensitive information by reading a file.

    Published: 25 Mar 2015
    6.8
    Medium

    CVE-2014-8925

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in ClearQuest Web in IBM Rational ClearQuest 7.1.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0.1.7 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout or insert XSS sequences.

    Published: 25 Mar 2015
    Unknown

    CVE-2015-0159

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3570. Reason: This candidate is a reservation duplicate of CVE-2014-3570. Notes: All CVE users should reference CVE-2014-3570 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Mar 2015
    7.5
    High

    CVE-2015-3138

    Last Modified: 20 Apr 2025

    print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).

    Published: 25 Mar 2015
    5.3
    Medium

    CVE-2015-1838

    Last Modified: 20 Apr 2025

    modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.

    Published: 25 Mar 2015
    5.3
    Medium

    CVE-2015-1839

    Last Modified: 20 Apr 2025

    modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.

    Published: 25 Mar 2015
    7.2
    High

    CVE-2015-1388

    Last Modified: 12 Apr 2025

    The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attackers to execute arbitrary commands via unspecified vectors.

    Published: 24 Mar 2015
    10
    Critical

    CVE-2015-2284

    Last Modified: 12 Apr 2025

    userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary code via unspecified vectors, related to client session handling.

    Published: 24 Mar 2015
    4.3
    Medium

    CVE-2015-0158

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Coach NG framework in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 24 Mar 2015
    7.2
    High

    CVE-2015-0197

    Last Modified: 12 Apr 2025

    IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to obtain root privileges for program execution via unspecified vectors.

    Published: 24 Mar 2015
    10
    Critical

    CVE-2015-0198

    Last Modified: 12 Apr 2025

    IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 in certain cipherList configurations allows remote attackers to bypass authentication and execute arbitrary programs as root via unspecified vectors.

    Published: 24 Mar 2015
    4.9
    Medium

    CVE-2015-0199

    Last Modified: 12 Apr 2025

    The mmfslinux kernel module in IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to cause a denial of service (memory corruption) via unspecified character-device ioctl calls.

    Published: 24 Mar 2015
    9.8
    Critical

    CVE-2014-0048

    Last Modified: 21 Nov 2024

    An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.

    Published: 24 Mar 2015
    6.8
    Medium

    CVE-2015-0279

    Last Modified: 12 Apr 2025

    JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.

    Published: 24 Mar 2015
    2.1
    Low

    CVE-2015-0527

    Last Modified: 12 Apr 2025

    EMC Documentum xCelerated Management System (xMS) 1.1 before P14 stores cleartext Windows Service credentials in a batch file during Documentum Platform and xCelerated Composition Platform (xCP) provisioning, which allows local users to obtain sensitive information by reading a file.

    Published: 24 Mar 2015
    4.3
    Medium

    CVE-2015-2776

    Last Modified: 12 Apr 2025

    The parse_SST function in FreeXL before 1.0.0i allows remote attackers to cause a denial of service (memory consumption) via a crafted shared strings table in a workbook.

    Published: 24 Mar 2015
    3.3
    Low

    CVE-2015-2922

    Last Modified: 12 Apr 2025

    The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.

    Published: 24 Mar 2015
    7.8
    High

    CVE-2014-0047

    Last Modified: 20 Apr 2025

    Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage.

    Published: 24 Mar 2015
    4.3
    Medium

    CVE-2015-0105

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 24 Mar 2015
    4.3
    Medium

    CVE-2015-0106

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 24 Mar 2015
    8.8
    High

    CVE-2014-8166

    Last Modified: 21 Nov 2024

    The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.

    Published: 24 Mar 2015
    3.5
    Low

    CVE-2015-0103

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Process Portal in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified data fields.

    Published: 24 Mar 2015
    2.1
    Low

    CVE-2015-0136

    Last Modified: 12 Apr 2025

    powervc-iso-import in IBM PowerVC 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 places an access token on the command line during IVM and PowerKVM management, which allows local users to obtain sensitive information by listing the process.

    Published: 24 Mar 2015
    4.3
    Medium

    CVE-2015-0137

    Last Modified: 12 Apr 2025

    IBM PowerVC Standard 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 validates Hardware Management Console (HMC) certificates only during the pre-login stage, which allows man-in-the-middle attackers to spoof devices via a crafted certificate.

    Published: 24 Mar 2015
    9.8
    Critical

    CVE-2015-1820

    Last Modified: 20 Apr 2025

    REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.

    Published: 24 Mar 2015
    6.8
    Medium

    CVE-2015-2753

    Last Modified: 12 Apr 2025

    FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly execute arbitrary code via a crafted sector in a workbook.

    Published: 24 Mar 2015
    6.8
    Medium

    CVE-2015-2754

    Last Modified: 12 Apr 2025

    FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) and possibly execute arbitrary code via a crafted workbook, related to a "premature EOF."

    Published: 24 Mar 2015
    6.8
    Medium

    CVE-2015-2676

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the ASUS RT-G32 routers with firmware 2.0.2.6 and 2.0.3.2 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request to start_apply.htm.

    Published: 23 Mar 2015
    3.5
    Low

    CVE-2015-2677

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ocPortal before 9.0.17 allow remote authenticated users to inject arbitrary web script or HTML via the (1) title or (2) text field in the cms_calendar page to cms/index.php; unspecified fields in (3) the cms_polls page to cms/index.php or (4) a new topic in the topics page to forum/index.php; or (5) a new PT (private topic/private message) in the topics page to forum/index.php.

    Published: 23 Mar 2015
    4.3
    Medium

    CVE-2015-2678

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter in the categories page to gxadmin/index.php or (2) page parameter to index.php.

    Published: 23 Mar 2015
    6.8
    Medium

    CVE-2015-2680

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request in the users page to gxadmin/index.php.

    Published: 23 Mar 2015
    4.3
    Medium

    CVE-2015-2681

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the ASUS RT-G32 routers with firmware 2.0.2.6 and 2.0.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) next_page, (2) group_id, (3) action_script, or (4) flag parameter to start_apply.htm.

    Published: 23 Mar 2015
    5
    Medium

    CVE-2014-9261

    Last Modified: 12 Apr 2025

    The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.

    Published: 23 Mar 2015
    3.5
    Low

    CVE-2015-2289

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in templates/2k11/admin/entries.tpl in Serendipity before 2.0.1 allows remote authenticated editors to inject arbitrary web script or HTML via the serendipity[cat][name] parameter to serendipity_admin.php, when creating a new category.

    Published: 23 Mar 2015
    7.5
    High

    CVE-2015-2679

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php or (2) username parameter to gxadmin/login.php.

    Published: 23 Mar 2015
    8.6
    High

    CVE-2015-1779

    Last Modified: 12 Apr 2025

    The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.

    Published: 23 Mar 2015
    7.8
    High

    CVE-2015-2325

    Last Modified: 21 Nov 2024

    The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bounds heap read and crash), or possibly have other unspecified impact via a regular expression with a group containing a forward reference repeated a large number of times within a repeated outer group that has a zero minimum quantifier.

    Published: 23 Mar 2015
    5.5
    Medium

    CVE-2015-2326

    Last Modified: 21 Nov 2024

    The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bounds read) via regular expression with a group containing both a forward referencing subroutine call and a recursive back reference, as demonstrated by "((?+1)(\1))/".

    Published: 23 Mar 2015
    4.3
    Medium

    CVE-2015-1812

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1813.

    Published: 23 Mar 2015
    4.3
    Medium

    CVE-2015-1813

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1812.

    Published: 23 Mar 2015