CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-0982

    Last Modified: 12 Apr 2025

    Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 14 Mar 2015
    9
    Critical

    CVE-2014-7884

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors.

    Published: 14 Mar 2015
    6.9
    Medium

    CVE-2014-9206

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Device Type Manager (DTM) 3.1.6 and earlier for Schneider Electric Invensys SRD Control Valve Positioner devices 960 and 991 allows local users to gain privileges via a malformed DLL file.

    Published: 14 Mar 2015
    6.9
    Medium

    CVE-2014-9207

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in CmnView.exe in CIMON CmnView 2.14.0.1 and 3.x before UltimateAccess 3.02 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 14 Mar 2015
    7.2
    High

    CVE-2015-0660

    Last Modified: 12 Apr 2025

    Cisco Virtual TelePresence Server Software does not properly restrict use of the serial port, which allows local users to execute arbitrary OS commands as root by leveraging vSphere controller administrative privileges, aka Bug ID CSCus61123.

    Published: 14 Mar 2015
    6.9
    Medium

    CVE-2015-0978

    Last Modified: 12 Apr 2025

    Multiple untrusted search path vulnerabilities in (1) EQATEC.Analytics.Monitor.Win32_vc100.dll and (2) EQATEC.Analytics.Monitor.Win32_vc100-x64.dll in Elipse E3 4.5.232 through 4.6.161 allow local users to gain privileges via a Trojan horse DLL in an unspecified directory. NOTE: this may overlap CVE-2015-2264.

    Published: 14 Mar 2015
    9
    Critical

    CVE-2015-0979

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to execute arbitrary code via a crafted packet.

    Published: 14 Mar 2015
    9
    Critical

    CVE-2015-0980

    Last Modified: 12 Apr 2025

    Format string vulnerability in BACnOPCServer.exe in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to execute arbitrary code via format string specifiers in a request.

    Published: 14 Mar 2015
    7.5
    High

    CVE-2015-0981

    Last Modified: 12 Apr 2025

    The SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to bypass authentication and read or write to arbitrary database fields via unspecified vectors.

    Published: 14 Mar 2015
    6.8
    Medium

    CVE-2015-2296

    Last Modified: 12 Apr 2025

    The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

    Published: 14 Mar 2015
    5
    Medium

    CVE-2015-2091

    Last Modified: 12 Apr 2025

    The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when "GnuTLSClientVerify require" is set, which allows remote attackers to spoof clients via a crafted certificate.

    Published: 13 Mar 2015
    3.5
    Low

    CVE-2014-6144

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 13 Mar 2015
    5
    Medium

    CVE-2015-0133

    Last Modified: 12 Apr 2025

    IBM WebSphere Commerce 7.0 Feature Pack 4 through 8 allows remote attackers to read arbitrary files and possibly obtain administrative privileges via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 13 Mar 2015
    6.8
    Medium

    CVE-2014-6214

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 13 Mar 2015
    3.5
    Low

    CVE-2015-0177

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 13 Mar 2015
    6.9
    Medium

    CVE-2015-2264

    Last Modified: 12 Apr 2025

    Multiple untrusted search path vulnerabilities in (1) EQATEC.Analytics.Monitor.Win32_vc100.dll and (2) EQATEC.Analytics.Monitor.Win32_vc100-x64.dll in Telerik Analytics Monitor Library before 3.2.125 allow local users to gain privileges via a Trojan horse (a) csunsapi.dll, (b) swift.dll, (c) nfhwcrhk.dll, or (d) surewarehook.dll file in an unspecified directory.

    Published: 13 Mar 2015
    3.5
    Low

    CVE-2015-0122

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0123.

    Published: 13 Mar 2015
    3.5
    Low

    CVE-2015-0123

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2015-0122.

    Published: 13 Mar 2015
    3.5
    Low

    CVE-2015-0129

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 13 Mar 2015
    3.5
    Low

    CVE-2015-0139

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 13 Mar 2015
    7.8
    High

    CVE-2015-0652

    Last Modified: 12 Apr 2025

    The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled exception and device reload) via a crafted media description, aka Bug IDs CSCus96593 and CSCun73192.

    Published: 13 Mar 2015
    10
    Critical

    CVE-2015-0653

    Last Modified: 12 Apr 2025

    The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs CSCur02680 and CSCur05556.

    Published: 13 Mar 2015
    7.1
    High

    CVE-2015-0654

    Last Modified: 12 Apr 2025

    Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to cause a denial of service (process hang) by establishing many HTTPS sessions, aka Bug ID CSCuq40652.

    Published: 13 Mar 2015
    7.5
    High

    CVE-2015-1818

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red Hat JBoss BPM Suite before 6.1.2 allows remote attackers to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and have other unspecified impact via a crafted XML document.

    Published: 13 Mar 2015
    7.5
    High

    CVE-2015-2237

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Betster (aka PHP Betoffice) 1.0.4 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showprofile.php or (2) categoryedit.php or (3) username parameter in a login to index.php.

    Published: 12 Mar 2015
    4.3
    Medium

    CVE-2015-2275

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to inject arbitrary web script or HTML via the parameters[data][7][title] parameter in a saveImageData action to index.php/AJAXProxy.

    Published: 12 Mar 2015
    7.5
    High

    CVE-2015-2208

    Last Modified: 12 Apr 2025

    The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the object parameter.

    Published: 12 Mar 2015
    7.2
    High

    CVE-2015-2285

    Last Modified: 12 Apr 2025

    The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu Vivid 15.04, allows local users to execute arbitrary commands and gain privileges via a crafted file in /run/user/*/upstart/sessions/.

    Published: 12 Mar 2015
    3.5
    Low

    CVE-2015-0521

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the CMP shared secret parameter.

    Published: 12 Mar 2015
    10
    Critical

    CVE-2015-1066

    Last Modified: 12 Apr 2025

    Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 12 Mar 2015
    4.3
    Medium

    CVE-2015-0522

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allows remote attackers to inject arbitrary web script or HTML via vectors related to the email address parameter.

    Published: 12 Mar 2015
    7.5
    High

    CVE-2015-0525

    Last Modified: 12 Apr 2025

    The Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 12 Mar 2015
    7.8
    High

    CVE-2015-0523

    Last Modified: 12 Apr 2025

    EMC RSA Certificate Manager (RCM) before 6.9 build 558 and RSA Registration Manager (RRM) before 6.9 build 558 allow remote attackers to cause an Administration Server denial of service via an invalid MIME e-mail message with a multipart/* Content-Type header.

    Published: 12 Mar 2015
    7.5
    High

    CVE-2015-0524

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 12 Mar 2015
    9.3
    Critical

    CVE-2015-1061

    Last Modified: 12 Apr 2025

    IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling.

    Published: 12 Mar 2015
    5
    Medium

    CVE-2015-1062

    Last Modified: 12 Apr 2025

    MobileStorageMounter in Apple iOS before 8.2 and Apple TV before 7.1 does not delete invalid disk-image folders, which allows attackers to create folders in arbitrary filesystem locations via a crafted app.

    Published: 12 Mar 2015
    7.8
    High

    CVE-2015-1063

    Last Modified: 12 Apr 2025

    CoreTelephony in Apple iOS before 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a Class 0 SMS message.

    Published: 12 Mar 2015
    1.9
    Low

    CVE-2015-1064

    Last Modified: 12 Apr 2025

    Springboard in Apple iOS before 8.2 allows physically proximate attackers to bypass an intended activation requirement and read the home screen by leveraging an application crash during the activation process.

    Published: 12 Mar 2015
    5.4
    Medium

    CVE-2015-1065

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in iCloud Keychain in Apple iOS before 8.2 and Apple OS X through 10.10.2 allow man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream during keychain recovery.

    Published: 12 Mar 2015
    10
    Critical

    CVE-2015-0333

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0332, CVE-2015-0335, and CVE-2015-0339.

    Published: 12 Mar 2015
    10
    Critical

    CVE-2015-0339

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0332, CVE-2015-0333, and CVE-2015-0335.

    Published: 12 Mar 2015
    9.3
    Critical

    CVE-2015-0334

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0336.

    Published: 12 Mar 2015
    5
    Medium

    CVE-2015-0340

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to bypass intended file-upload restrictions via unspecified vectors.

    Published: 12 Mar 2015
    9.3
    Critical

    CVE-2015-3331

    Last Modified: 12 Apr 2025

    The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attackers to cause a denial of service (buffer overflow and system crash) or possibly execute arbitrary code by triggering a crypto API call, as demonstrated by use of a libkcapi test program with an AF_ALG(aead) socket.

    Published: 12 Mar 2015
    7.5
    High

    CVE-2015-8852

    Last Modified: 12 Apr 2025

    Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.

    Published: 12 Mar 2015
    10
    Critical

    CVE-2015-0332

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0333, CVE-2015-0335, and CVE-2015-0339.

    Published: 12 Mar 2015
    10
    Critical

    CVE-2015-0335

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0332, CVE-2015-0333, and CVE-2015-0339.

    Published: 12 Mar 2015
    9.3
    Critical

    CVE-2015-0336

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0334.

    Published: 12 Mar 2015
    5
    Medium

    CVE-2015-0337

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 12 Mar 2015
    10
    Critical

    CVE-2015-0338

    Last Modified: 12 Apr 2025

    Integer overflow in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors.

    Published: 12 Mar 2015