CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2015-1078

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1079

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1080

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1081

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1082

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-1083

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.

    Published: 18 Mar 2015
    3.5
    Low

    CVE-2015-2149

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the (1) MIME-type field in an add action in the config-attachment_types module to admin/index.php; (2) title or (3) short description field in an add action in the (a) config-mycode or (b) user-groups module to admin/index.php; (4) title field in an add action in the (c) forum-management or (d) tool-tasks module to admin/index.php; (5) name field in an add_set action in the style-templates module to admin/index.php; (6) title field in an add_template_group action in the style-templates module to admin/index.php; (7) name field in an add action in the config-post_icons module to admin/index.php; (8) "title to assign" field in an add action in the user-titles module to admin/index.php; or (9) username field in the config-banning module to admin/index.php.

    Published: 18 Mar 2015
    4.3
    Medium

    CVE-2015-2332

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in member.php in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Mar 2015
    4.3
    Medium

    CVE-2015-2333

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Mar 2015
    6.8
    Medium

    CVE-2015-2334

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Admin Control Panel (ACP) login in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 18 Mar 2015
    5
    Medium

    CVE-2015-2335

    Last Modified: 12 Apr 2025

    A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.

    Published: 18 Mar 2015
    5.5
    Medium

    CVE-2014-6129

    Last Modified: 12 Apr 2025

    IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational DOORS Next Generation 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5; and other products, allows remote authenticated users to delete the dashboards of arbitrary users via unspecified vectors.

    Published: 18 Mar 2015
    4
    Medium

    CVE-2014-6131

    Last Modified: 12 Apr 2025

    IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix5, 4.x before 4.0.7 iFix4, and 5.x before 5.0.2 iFix2; Rational DOORS Next Generation 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2; Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5; and other products, allows remote authenticated users to read the dashboards of arbitrary users via unspecified vectors.

    Published: 18 Mar 2015
    2.1
    Low

    CVE-2015-0146

    Last Modified: 12 Apr 2025

    IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNet P8 systems with IBM Content Search Services, which allows local users to bypass intended document-access restrictions and obtain sensitive information via a crafted search query.

    Published: 18 Mar 2015
    3.5
    Low

    CVE-2015-0124

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0128.

    Published: 18 Mar 2015
    3.5
    Low

    CVE-2015-0125

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 4.x before 4.0.7 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 18 Mar 2015
    3.5
    Low

    CVE-2015-0128

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x and 3.x before 3.0.1.6 iFix4, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0124.

    Published: 18 Mar 2015
    7.8
    High

    CVE-2015-0132

    Last Modified: 12 Apr 2025

    The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5 and 4.x before 4.0.7 iFix3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Published: 18 Mar 2015
    5.5
    Medium

    CVE-2015-0149

    Last Modified: 12 Apr 2025

    The developer portal in IBM API Management 3.0 before 3.0.4.1 does not properly restrict access to the public and private APIs, which allows remote authenticated users to obtain sensitive information or modify data via unspecified API calls.

    Published: 18 Mar 2015
    4.3
    Medium

    CVE-2015-0178

    Last Modified: 12 Apr 2025

    The Java overlay feature in IBM Bluemix Liberty before 1.13-20150209-1122 for Java does not properly support WAR applications, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 18 Mar 2015
    7.5
    High

    CVE-2015-2331

    Last Modified: 12 Apr 2025

    Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.

    Published: 18 Mar 2015
    5
    Medium

    CVE-2015-2316

    Last Modified: 12 Apr 2025

    The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.

    Published: 18 Mar 2015
    4.3
    Medium

    CVE-2015-2317

    Last Modified: 12 Apr 2025

    The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.

    Published: 18 Mar 2015
    5.5
    Medium

    CVE-2015-2672

    Last Modified: 12 Apr 2025

    The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altinstr_replacement pointers and consequently does not provide any protection against instruction faulting, which allows local users to cause a denial of service (panic) by triggering a fault, as demonstrated by an unaligned memory operand or a non-canonical address memory operand.

    Published: 18 Mar 2015
    6.5
    Medium

    CVE-2015-2292

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) order_by or (2) order parameter in the wpseo_bulk-editor page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

    Published: 17 Mar 2015
    6.8
    Medium

    CVE-2015-2293

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote attackers to hijack the authentication of certain users for requests that conduct SQL injection attacks via the (1) order_by or (2) order parameter in the wpseo_bulk-editor page.

    Published: 17 Mar 2015
    7.5
    High

    CVE-2015-2314

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.

    Published: 17 Mar 2015
    4.3
    Medium

    CVE-2015-2315

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup action to the default URI.

    Published: 17 Mar 2015
    6.6
    Medium

    CVE-2015-0665

    Last Modified: 12 Apr 2025

    The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary files via crafted IPC messages, aka Bug ID CSCus79173.

    Published: 17 Mar 2015
    7.2
    High

    CVE-2015-0662

    Last Modified: 12 Apr 2025

    Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to gain privileges via crafted IPC messages that trigger use of root privileges for a software-package installation, aka Bug ID CSCus79385.

    Published: 17 Mar 2015
    6.6
    Medium

    CVE-2015-0663

    Last Modified: 12 Apr 2025

    Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users to write to arbitrary files via crafted messages, aka Bug ID CSCus79392.

    Published: 17 Mar 2015
    5
    Medium

    CVE-2015-0264

    Last Modified: 12 Apr 2025

    Multiple XML external entity (XXE) vulnerabilities in builder/xml/XPathBuilder.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allow remote attackers to read arbitrary files via an external entity in an invalid XML (1) String or (2) GenericFile object in an XPath query.

    Published: 17 Mar 2015
    8.5
    High

    CVE-2015-1802

    Last Modified: 12 Apr 2025

    The bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 allows remote authenticated users to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a (1) negative or (2) large property count in a BDF font file.

    Published: 17 Mar 2015
    8.5
    High

    CVE-2015-1803

    Last Modified: 12 Apr 2025

    The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly handle character bitmaps it cannot read, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a crafted BDF font file.

    Published: 17 Mar 2015
    9.8
    Critical

    CVE-2014-3699

    Last Modified: 21 Nov 2024

    eDeploy has RCE via cPickle deserialization of untrusted data

    Published: 17 Mar 2015
    9.8
    Critical

    CVE-2014-3700

    Last Modified: 21 Nov 2024

    eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data

    Published: 17 Mar 2015
    8.1
    High

    CVE-2014-3701

    Last Modified: 21 Nov 2024

    eDeploy has tmp file race condition flaws

    Published: 17 Mar 2015
    9.1
    Critical

    CVE-2014-3702

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a denial of service (resource consumption) via a .. (dot dot) the session parameter.

    Published: 17 Mar 2015
    9.8
    Critical

    CVE-2014-8174

    Last Modified: 20 Apr 2025

    eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files.

    Published: 17 Mar 2015
    5
    Medium

    CVE-2015-0263

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary files via an external entity in an SAXSource.

    Published: 17 Mar 2015
    8.5
    High

    CVE-2015-1804

    Last Modified: 12 Apr 2025

    The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion for metrics values, which allows remote authenticated users to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via a crafted BDF font file.

    Published: 17 Mar 2015
    7.5
    High

    CVE-2015-2330

    Last Modified: 20 Apr 2025

    Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, including, for example, secure cookies.

    Published: 17 Mar 2015
    7.3
    High

    CVE-2015-8955

    Last Modified: 12 Apr 2025

    arch/arm64/kernel/perf_event.c in the Linux kernel before 4.1 on arm64 platforms allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via vectors involving events that are mishandled during a span of multiple HW PMUs.

    Published: 17 Mar 2015
    7.5
    High

    CVE-2015-0778

    Last Modified: 12 Apr 2025

    osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.

    Published: 16 Mar 2015
    5
    Medium

    CVE-2009-5146

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 16 Mar 2015
    7.8
    High

    CVE-2015-1795

    Last Modified: 20 Apr 2025

    Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.

    Published: 16 Mar 2015
    6.1
    Medium

    CVE-2014-6393

    Last Modified: 20 Apr 2025

    The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

    Published: 15 Mar 2015
    6.4
    Medium

    CVE-2014-5409

    Last Modified: 3 Nov 2025

    The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values.

    Published: 14 Mar 2015
    10
    Critical

    CVE-2014-7885

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vectors.

    Published: 14 Mar 2015
    6.8
    Medium

    CVE-2015-2107

    Last Modified: 12 Apr 2025

    HP Operations Manager i Management Pack 1.x before 1.01 for SAP allows local users to execute OS commands by leveraging SAP administrative privileges.

    Published: 14 Mar 2015