CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2015-3010

    Last Modified: 12 Apr 2025

    ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.

    Published: 5 Mar 2015
    5
    Medium

    CVE-2014-8105

    Last Modified: 12 Apr 2025

    389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.

    Published: 5 Mar 2015
    4
    Medium

    CVE-2014-8112

    Last Modified: 12 Apr 2025

    389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.

    Published: 5 Mar 2015
    8.8
    High

    CVE-2014-8170

    Last Modified: 20 Apr 2025

    ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate attackers to execute arbitrary commands via a ; (semicolon) in an input string.

    Published: 5 Mar 2015
    4
    Medium

    CVE-2015-0271

    Last Modified: 12 Apr 2025

    The log-viewing function in the Red Hat redhat-access-plugin before 6.0.3 for OpenStack Dashboard (horizon) allows remote attackers to read arbitrary files via a crafted path.

    Published: 5 Mar 2015
    7.2
    High

    CVE-2015-0274

    Last Modified: 12 Apr 2025

    The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leveraging XFS filesystem access.

    Published: 5 Mar 2015
    6.5
    Medium

    CVE-2015-1780

    Last Modified: 21 Nov 2024

    oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center

    Published: 5 Mar 2015
    5
    Medium

    CVE-2015-2209

    Last Modified: 12 Apr 2025

    DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php.

    Published: 4 Mar 2015
    4.3
    Medium

    CVE-2014-8617

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI in Fortinet FortiMail before 4.3.9, 5.0.x before 5.0.8, 5.1.x before 5.1.5, and 5.2.x before 5.2.3 allows remote attackers to inject arbitrary web script or HTML via the release parameter to module/releasecontrol.

    Published: 4 Mar 2015
    4.3
    Medium

    CVE-2015-0656

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the login page in Cisco Network Analysis Module (NAM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCum81269.

    Published: 4 Mar 2015
    3.5
    Low

    CVE-2015-0933

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in ShareLaTeX 0.1.3 and earlier, when the paranoid openin_any setting is omitted, allows remote authenticated users to read arbitrary files via a \include command.

    Published: 4 Mar 2015
    6.5
    Medium

    CVE-2015-0934

    Last Modified: 12 Apr 2025

    Common LaTeX Service Interface (CLSI) before 0.1.3, as used in ShareLaTeX before 0.1.3, allows remote authenticated users to execute arbitrary code via ` (backtick) characters in a filename.

    Published: 4 Mar 2015
    5
    Medium

    CVE-2015-2189

    Last Modified: 12 Apr 2025

    Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via an invalid Interface Statistics Block (ISB) interface ID in a crafted packet.

    Published: 4 Mar 2015
    5
    Medium

    CVE-2015-2187

    Last Modified: 12 Apr 2025

    The dissect_atn_cpdlc_heur function in asn1/atn-cpdlc/packet-atn-cpdlc-template.c in the ATN-CPDLC dissector in Wireshark 1.12.x before 1.12.4 does not properly follow the TRY/ENDTRY code requirements, which allows remote attackers to cause a denial of service (stack memory corruption and application crash) via a crafted packet.

    Published: 4 Mar 2015
    5
    Medium

    CVE-2015-2190

    Last Modified: 12 Apr 2025

    epan/proto.c in Wireshark 1.12.x before 1.12.4 does not properly handle integer data types greater than 32 bits in size, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet that is improperly handled by the LLDP dissector.

    Published: 4 Mar 2015
    5
    Medium

    CVE-2015-2192

    Last Modified: 12 Apr 2025

    Integer overflow in the dissect_osd2_cdb_continuation function in epan/dissectors/packet-scsi-osd.c in the SCSI OSD dissector in Wireshark 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted length field in a packet.

    Published: 4 Mar 2015
    5.9
    Medium

    CVE-2015-1777

    Last Modified: 21 Nov 2024

    rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attackers to prevent system registration via a man-in-the-middle attack.

    Published: 4 Mar 2015
    5
    Medium

    CVE-2015-2188

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet that is improperly handled during decompression.

    Published: 4 Mar 2015
    5
    Medium

    CVE-2015-2191

    Last Modified: 12 Apr 2025

    Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted length field in a packet.

    Published: 4 Mar 2015
    4.3
    Medium

    CVE-2015-2195

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the WP Media Cleaner plugin 2.2.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) view, (2) paged, or (3) s parameter in the wp-media-cleaner page to wp-admin/upload.php.

    Published: 3 Mar 2015
    3.5
    Low

    CVE-2015-2197

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Entity API module before 7.x-1.6 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a field label in the Token API.

    Published: 3 Mar 2015
    6.5
    Medium

    CVE-2015-2199

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via the item[id] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or remote administrators to execute arbitrary SQL commands via the itemid parameter in the (2) wonderplugin_audio_show_item, (3) wonderplugin_audio_show_items, or (4) wonderplugin_audio_edit_item page to wp-admin/admin.php.

    Published: 3 Mar 2015
    4.3
    Medium

    CVE-2015-2198

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage_url, (2) pic_url, or (3) avatar_url parameter, which are not properly handled in an error message.

    Published: 3 Mar 2015
    6.5
    Medium

    CVE-2015-2194

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the fusion_options function in functions.php in the Fusion theme 3.1 for Wordpress allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension in a fusion_save action, then accessing it via unspecified vectors.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-2196

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.

    Published: 3 Mar 2015
    5
    Medium

    CVE-2015-0890

    Last Modified: 12 Apr 2025

    The BestWebSoft Google Captcha (aka reCAPTCHA) plugin before 1.13 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

    Published: 3 Mar 2015
    4.3
    Medium

    CVE-2014-7896

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, as used in HP Device Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Tiered Storage Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Replication Manager 6.x and 7.x before 7.6.1-06, and HP XP7 Global Link Manager Software (aka HGLM) 6.x through 8.x before 8.1.2-00, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Mar 2015
    5
    Medium

    CVE-2014-9283

    Last Modified: 12 Apr 2025

    The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

    Published: 3 Mar 2015
    Unknown

    CVE-2015-2168

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue in customer-controlled software. Notes: none

    Published: 3 Mar 2015
    5.4
    Medium

    CVE-2015-0284

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1219

    Last Modified: 12 Apr 2025

    Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted allocation of a large amount of memory during WebGL rendering.

    Published: 3 Mar 2015
    5
    Medium

    CVE-2015-1226

    Last Modified: 12 Apr 2025

    The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properly restrict what URLs are available as debugger targets, which allows remote attackers to bypass intended access restrictions via a crafted extension.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1232

    Last Modified: 12 Apr 2025

    Array index error in the MidiManagerUsb::DispatchSendMidiData function in media/midi/midi_manager_usb.cc in Google Chrome before 41.0.2272.76 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging renderer access to provide an invalid port index that triggers an out-of-bounds write operation, a different vulnerability than CVE-2015-1212.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1214

    Last Modified: 12 Apr 2025

    Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a reset action with a large count value, leading to an out-of-bounds write operation.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1215

    Last Modified: 12 Apr 2025

    The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1216

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the V8Window::namedPropertyGetterCustom function in bindings/core/v8/custom/V8WindowCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a frame detachment.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1218

    Last Modified: 12 Apr 2025

    Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger movement of a SCRIPT element to different documents, related to (1) the HTMLScriptElement::didMoveToNewDocument function in core/html/HTMLScriptElement.cpp and (2) the SVGScriptElement::didMoveToNewDocument function in core/svg/SVGScriptElement.cpp.

    Published: 3 Mar 2015
    6.8
    Medium

    CVE-2015-1220

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted frame size in a GIF image.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1227

    Last Modified: 12 Apr 2025

    The DragImage::create function in platform/DragImage.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not initialize memory for image drawing, which allows remote attackers to have an unspecified impact by triggering a failed image decoding, as demonstrated by an image for which the default orientation cannot be used.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-4147

    Last Modified: 12 Apr 2025

    The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_headers is an array, which allows remote attackers to execute arbitrary code by providing crafted serialized data with an unexpected data type, related to a "type confusion" issue.

    Published: 3 Mar 2015
    6.5
    Medium

    CVE-2014-8163

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1213

    Last Modified: 12 Apr 2025

    The SkBitmap::ReadRawPixels function in core/SkBitmap.cpp in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1217

    Last Modified: 12 Apr 2025

    The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

    Published: 3 Mar 2015
    5
    Medium

    CVE-2015-1225

    Last Modified: 12 Apr 2025

    PDFium, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1221

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect ordering of operations in the Web SQL Database thread relative to Blink's main thread, related to the shutdown function in web/WebKit.cpp.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1222

    Last Modified: 12 Apr 2025

    Multiple use-after-free vulnerabilities in the ServiceWorkerScriptCacheMap implementation in content/browser/service_worker/service_worker_script_cache_map.cc in Google Chrome before 41.0.2272.76 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a ServiceWorkerContextWrapper::DeleteAndStartOver call, related to the NotifyStartedCaching and NotifyFinishedCaching functions.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1223

    Last Modified: 12 Apr 2025

    Multiple use-after-free vulnerabilities in core/html/HTMLInputElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger extraneous change events, as demonstrated by events for invalid input or input to read-only fields, related to the initializeTypeInParsing and updateType functions.

    Published: 3 Mar 2015
    5
    Medium

    CVE-2015-1224

    Last Modified: 12 Apr 2025

    The VpxVideoDecoder::VpxDecode function in media/filters/vpx_video_decoder.cc in the vpxdecoder implementation in Google Chrome before 41.0.2272.76 does not ensure that alpha-plane dimensions are identical to image dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted VPx video data.

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1228

    Last Modified: 12 Apr 2025

    The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not initialize memory for a data structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted Cascading Style Sheets (CSS) token sequence.

    Published: 3 Mar 2015
    5
    Medium

    CVE-2015-1229

    Last Modified: 12 Apr 2025

    net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response.

    Published: 3 Mar 2015