CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-1814

    Last Modified: 12 Apr 2025

    The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.

    Published: 23 Mar 2015
    5.9
    Medium

    CVE-2015-1849

    Last Modified: 20 Apr 2025

    AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logging is enabled.

    Published: 23 Mar 2015
    4.3
    Medium

    CVE-2015-0941

    Last Modified: 12 Apr 2025

    The Inetc plugin for Nullsoft Scriptable Install System (NSIS), as used in CERT/CC Failure Observation Engine (FOE) and other products, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and possibly execute arbitrary code by sending a crafted certificate in a download session for Windows executable files.

    Published: 22 Mar 2015
    4.6
    Medium

    CVE-2015-5707

    Last Modified: 12 Apr 2025

    Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.

    Published: 22 Mar 2015
    6.4
    Medium

    CVE-2015-0670

    Last Modified: 12 Apr 2025

    The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does not properly support authentication, which allows remote attackers to read audio-stream data or originate telephone calls via a crafted XML request, aka Bug ID CSCuo52482.

    Published: 21 Mar 2015
    6.4
    Medium

    CVE-2015-0669

    Last Modified: 12 Apr 2025

    The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 15.4S and 15.4(3)S allows remote attackers to modify configuration settings or cause a denial of service (partial service outage) by sending crafted Autonomic Networking (AN) messages on an intranet network, aka Bug ID CSCup62167.

    Published: 21 Mar 2015
    7.5
    High

    CVE-2015-0898

    Last Modified: 12 Apr 2025

    futomi CGI Cafe MP Form Mail CGI eCommerce before 2.0.12 on Windows allows remote attackers to execute arbitrary Perl code via unspecified vectors.

    Published: 21 Mar 2015
    6.8
    Medium

    CVE-2015-0817

    Last Modified: 12 Apr 2025

    The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaMonkey before 2.33.1 does not properly determine the cases in which bounds checking may be safely skipped during JIT compilation and heap access, which allows remote attackers to read or write to unintended memory locations, and consequently execute arbitrary code, via crafted JavaScript.

    Published: 21 Mar 2015
    7.8
    High

    CVE-2015-8830

    Last Modified: 12 Apr 2025

    Integer overflow in the aio_setup_single_vector function in fs/aio.c in the Linux kernel 4.0 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec. NOTE: this vulnerability exists because of a CVE-2012-6701 regression.

    Published: 21 Mar 2015
    7.5
    High

    CVE-2015-0818

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving SVG hash navigation.

    Published: 21 Mar 2015
    7.5
    High

    CVE-2015-2562

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) search_category_id, (2) sort_order, or (3) filter_manufacturer_ids in a displayproducts action to index.php.

    Published: 20 Mar 2015
    7.5
    High

    CVE-2015-2563

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 0.9.9 and 1.2.3 allows remote attackers to execute arbitrary SQL commands via the order_by parameter. NOTE: The cat parameter vector is already covered by CVE-2008-4157.

    Published: 20 Mar 2015
    6.5
    Medium

    CVE-2015-2564

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to users-edit.php.

    Published: 20 Mar 2015
    4.3
    Medium

    CVE-2015-0668

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the administration portal in Cisco WebEx Meetings Server 2.5 and 2.5.99.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuq66737.

    Published: 20 Mar 2015
    5
    Medium

    CVE-2015-0671

    Last Modified: 12 Apr 2025

    The DNS implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.2(1) allows remote attackers to cause a denial of service (CPU consumption and network-resource consumption) via crafted packets, aka Bug ID CSCun15911.

    Published: 20 Mar 2015
    7.8
    High

    CVE-2015-2686

    Last Modified: 12 Apr 2025

    net/socket.c in the Linux kernel 3.19 before 3.19.3 does not validate certain range data for (1) sendto and (2) recvfrom system calls, which allows local users to gain privileges by leveraging a subsystem that uses the copy_from_iter function in the iov_iter interface, as demonstrated by the Bluetooth subsystem.

    Published: 20 Mar 2015
    9.8
    Critical

    CVE-2015-4602

    Last Modified: 12 Apr 2025

    The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

    Published: 20 Mar 2015
    5
    Medium

    CVE-2015-0252

    Last Modified: 12 Apr 2025

    internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.

    Published: 20 Mar 2015
    4.3
    Medium

    CVE-2015-2349

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in SuperWebMailer 5.60.0.01190 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTMLForm parameter.

    Published: 19 Mar 2015
    4.3
    Medium

    CVE-2015-2351

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms 9.5.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) homelink parameter to system/modules/org.opencms.workplace.help/jsptemplates/help_head.jsp, (2) workplaceresource parameter to system/workplace/locales/en/help/index.html, (3) path parameter to system/workplace/views/admin/admin-main.jsp, (4) mode parameter to system/workplace/views/explorer/explorer_files.jsp, or (5) query parameter in a search action to system/modules/org.opencms.workplace.help/elements/search.jsp.

    Published: 19 Mar 2015
    7.5
    High

    CVE-2015-2281

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message Dispatcher on TCP port 8000.

    Published: 19 Mar 2015
    6.8
    Medium

    CVE-2015-2350

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request in the status page to /cfg.

    Published: 19 Mar 2015
    7.5
    High

    CVE-2015-2352

    Last Modified: 12 Apr 2025

    The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the var_export function, which allows attackers to have an unspecified impact via unknown vectors.

    Published: 19 Mar 2015
    4.3
    Medium

    CVE-2015-0208

    Last Modified: 12 Apr 2025

    The ASN.1 signature-verification implementation in the rsa_item_verify function in crypto/rsa/rsa_ameth.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted RSA PSS parameters to an endpoint that uses the certificate-verification feature.

    Published: 19 Mar 2015
    5
    Medium

    CVE-2015-0291

    Last Modified: 12 Apr 2025

    The sigalgs implementation in t1_lib.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by using an invalid signature_algorithms extension in the ClientHello message during a renegotiation.

    Published: 19 Mar 2015
    2.6
    Low

    CVE-2015-1787

    Last Modified: 12 Apr 2025

    The ssl3_get_client_key_exchange function in s3_srvr.c in OpenSSL 1.0.2 before 1.0.2a, when client authentication and an ephemeral Diffie-Hellman ciphersuite are enabled, allows remote attackers to cause a denial of service (daemon crash) via a ClientKeyExchange message with a length of zero.

    Published: 19 Mar 2015
    5.5
    Medium

    CVE-2014-0219

    Last Modified: 20 Apr 2025

    Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports.

    Published: 19 Mar 2015
    4.3
    Medium

    CVE-2015-0285

    Last Modified: 12 Apr 2025

    The ssl3_client_hello function in s3_clnt.c in OpenSSL 1.0.2 before 1.0.2a does not ensure that the PRNG is seeded before proceeding with a handshake, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and then conducting a brute-force attack.

    Published: 19 Mar 2015
    7.5
    High

    CVE-2015-0292

    Last Modified: 12 Apr 2025

    Integer underflow in the EVP_DecodeUpdate function in crypto/evp/encode.c in the base64-decoding implementation in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted base64 data that triggers a buffer overflow.

    Published: 19 Mar 2015
    5
    Medium

    CVE-2015-0207

    Last Modified: 12 Apr 2025

    The dtls1_listen function in d1_lib.c in OpenSSL 1.0.2 before 1.0.2a does not properly isolate the state information of independent data streams, which allows remote attackers to cause a denial of service (application crash) via crafted DTLS traffic, as demonstrated by DTLS 1.0 traffic to a DTLS 1.2 server.

    Published: 19 Mar 2015
    5
    Medium

    CVE-2015-0286

    Last Modified: 12 Apr 2025

    The ASN1_TYPE_cmp function in crypto/asn1/a_type.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly perform boolean-type comparisons, which allows remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted X.509 certificate to an endpoint that uses the certificate-verification feature.

    Published: 19 Mar 2015
    5
    Medium

    CVE-2015-0287

    Last Modified: 12 Apr 2025

    The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure reuse.

    Published: 19 Mar 2015
    5
    Medium

    CVE-2015-0288

    Last Modified: 12 Apr 2025

    The X509_to_X509_REQ function in crypto/x509/x509_req.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow attackers to cause a denial of service (NULL pointer dereference and application crash) via an invalid certificate key.

    Published: 19 Mar 2015
    5
    Medium

    CVE-2015-0289

    Last Modified: 12 Apr 2025

    The PKCS#7 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly handle a lack of outer ContentInfo, which allows attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an application that processes arbitrary PKCS#7 data and providing malformed data with ASN.1 encoding, related to crypto/pkcs7/pk7_doit.c and crypto/pkcs7/pk7_lib.c.

    Published: 19 Mar 2015
    5
    Medium

    CVE-2015-0290

    Last Modified: 12 Apr 2025

    The multi-block feature in the ssl3_write_bytes function in s3_pkt.c in OpenSSL 1.0.2 before 1.0.2a on 64-bit x86 platforms with AES NI support does not properly handle certain non-blocking I/O cases, which allows remote attackers to cause a denial of service (pointer corruption and application crash) via unspecified vectors.

    Published: 19 Mar 2015
    5
    Medium

    CVE-2015-0293

    Last Modified: 12 Apr 2025

    The SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (s2_lib.c assertion failure and daemon exit) via a crafted CLIENT-MASTER-KEY message.

    Published: 19 Mar 2015
    5
    Medium

    CVE-2015-0667

    Last Modified: 12 Apr 2025

    The Management Interface on Cisco Content Services Switch (CSS) 11500 devices 8.20.4.02 and earlier allows remote attackers to bypass intended restrictions on local-network device access via crafted SSH packets, aka Bug ID CSCut14855.

    Published: 18 Mar 2015
    4.3
    Medium

    CVE-2015-0896

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Mar 2015
    4.3
    Medium

    CVE-2015-0664

    Last Modified: 12 Apr 2025

    The IPC channel in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary userspace memory locations, and consequently gain privileges, via crafted messages, aka Bug ID CSCus79195.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1072

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1077

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    5
    Medium

    CVE-2015-1084

    Last Modified: 12 Apr 2025

    The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, does not display URLs consistently, which makes it easier for remote attackers to conduct phishing attacks via a crafted URL.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1068

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1073

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1074

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1069

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1070

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1071

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1075

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1076

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015