CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-1230

    Last Modified: 12 Apr 2025

    The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that adds an AudioContext event listener and triggers "type confusion."

    Published: 3 Mar 2015
    7.5
    High

    CVE-2015-1231

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 3 Mar 2015
    5
    Medium

    CVE-2015-4148

    Last Modified: 12 Apr 2025

    The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property is a string, which allows remote attackers to obtain sensitive information by providing crafted serialized data with an int data type, related to a "type confusion" issue.

    Published: 3 Mar 2015
    9.8
    Critical

    CVE-2015-4603

    Last Modified: 12 Apr 2025

    The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

    Published: 3 Mar 2015
    4.3
    Medium

    CVE-2014-8921

    Last Modified: 12 Apr 2025

    The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a phishing attack involving an encrypted e-mail message.

    Published: 2 Mar 2015
    4.4
    Medium

    CVE-2014-8169

    Last Modified: 12 Apr 2025

    automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environment variable values instead of the values for the user used to run the mapped program, which allows local users to gain privileges via a Trojan horse program in the user home directory.

    Published: 2 Mar 2015
    5
    Medium

    CVE-2015-2348

    Last Modified: 12 Apr 2025

    The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extension restrictions and create files with unexpected names via a crafted second argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.

    Published: 2 Mar 2015
    7.5
    High

    CVE-2015-2787

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages use of the unset function within an __wakeup function, a related issue to CVE-2015-0231.

    Published: 2 Mar 2015
    4.3
    Medium

    CVE-2015-0655

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Unified Web Interaction Manager in Cisco Unified Web and E-Mail Interaction Manager allows remote attackers to inject arbitrary web script or HTML via vectors related to a POST request, aka Bug ID CSCus74184.

    Published: 28 Feb 2015
    6.9
    Medium

    CVE-2015-0884

    Last Modified: 12 Apr 2025

    Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.

    Published: 28 Feb 2015
    5
    Medium

    CVE-2015-0885

    Last Modified: 12 Apr 2025

    checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.

    Published: 28 Feb 2015
    7.1
    High

    CVE-2015-0887

    Last Modified: 12 Apr 2025

    npppd in the PPP Access Concentrator (PPPAC) on SEIL SEIL/x86 Fuji routers 1.00 through 3.30, SEIL/X1 routers 3.50 through 4.70, SEIL/X2 routers 3.50 through 4.70, and SEIL/B1 routers 3.50 through 4.70 allows remote attackers to cause a denial of service (infinite loop and device hang) via a crafted SSTP packet.

    Published: 28 Feb 2015
    6.4
    Medium

    CVE-2015-0888

    Last Modified: 12 Apr 2025

    KENT-WEB Clip Board before 4.1 allows remote attackers to delete arbitrary files via unspecified vectors.

    Published: 28 Feb 2015
    7.5
    High

    CVE-2015-0889

    Last Modified: 12 Apr 2025

    KENT-WEB Joyful Note before 5.3 allows remote attackers to delete files or write to files, and consequently execute arbitrary code, via vectors involving an article.

    Published: 28 Feb 2015
    6.8
    Medium

    CVE-2014-9676

    Last Modified: 12 Apr 2025

    The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memory handler") and possibly execute arbitrary code via a crafted video that triggers a use after free.

    Published: 28 Feb 2015
    10
    Critical

    CVE-2014-9682

    Last Modified: 12 Apr 2025

    The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.

    Published: 28 Feb 2015
    5.9
    Medium

    CVE-2015-8985

    Last Modified: 20 Apr 2025

    The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion failure and application crash) via vectors related to extended regular expression processing.

    Published: 28 Feb 2015
    5
    Medium

    CVE-2015-2075

    Last Modified: 12 Apr 2025

    SAP BusinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011396.

    Published: 27 Feb 2015
    5
    Medium

    CVE-2015-2076

    Last Modified: 12 Apr 2025

    The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information by reading an audit event, aka SAP Note 2011395.

    Published: 27 Feb 2015
    4.3
    Medium

    CVE-2015-2103

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the admin-login panel (admin/index.cgi) in Cosmoshop allows remote attackers to inject arbitrary web script or HTML via the username field (u_name parameter).

    Published: 27 Feb 2015
    7.8
    High

    CVE-2015-1414

    Last Modified: 12 Apr 2025

    Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.

    Published: 27 Feb 2015
    4.3
    Medium

    CVE-2015-2072

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) ide/core/plugins/editor/templates/trace/hanaTraceDetailService.xsjs or (2) xs/ide/editor/templates/trace/hanaTraceDetailService.xsjs, aka SAP Note 2069676.

    Published: 27 Feb 2015
    4.3
    Medium

    CVE-2015-2101

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Navigate bar in the Navigate module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Feb 2015
    7.5
    High

    CVE-2015-2102

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execute arbitrary SQL commands via the item parameter.

    Published: 27 Feb 2015
    4.3
    Medium

    CVE-2015-0882

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in zencart-ja (aka Zen Cart Japanese edition) 1.3 jp through 1.3.0.2 jp8 and 1.5 ja through 1.5.1 ja allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, related to admin/includes/init_includes/init_sanitize.php and includes/init_includes/init_sanitize.php.

    Published: 27 Feb 2015
    Unknown

    CVE-2014-2188

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-0607. Reason: This candidate is a duplicate of CVE-2015-0607. The wrong ID was used. Notes: All CVE users should reference CVE-2015-0607 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Feb 2015
    4.3
    Medium

    CVE-2015-0594

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS) and Cisco Security Manager, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuq54654 and CSCun18263.

    Published: 27 Feb 2015
    6.8
    Medium

    CVE-2015-0651

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web GUI in Cisco Application Networking Manager (ANM), and Device Manager (DM) on Cisco 4710 Application Control Engine (ACE) appliances, allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuo99753.

    Published: 27 Feb 2015
    6.8
    Medium

    CVE-2015-0883

    Last Modified: 12 Apr 2025

    SYNCK GRAPHICA Mailform Pro CGI 4.1.4 and 4.1.5, when the mailauth module is enabled, does not properly send e-mail messages, which allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 27 Feb 2015
    5.7
    Medium

    CVE-2015-0632

    Last Modified: 12 Apr 2025

    Race condition in the Neighbor Discovery (ND) protocol implementation in Cisco IOS and IOS XE allows remote attackers to cause a denial of service via a flood of Router Solicitation messages on the local network, aka Bug ID CSCuo67770.

    Published: 27 Feb 2015
    10
    Critical

    CVE-2015-0977

    Last Modified: 12 Apr 2025

    Network Vision IntraVue before 2.3.0a14 on Windows allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 27 Feb 2015
    5.9
    Medium

    CVE-2012-6702

    Last Modified: 12 Apr 2025

    Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.

    Published: 27 Feb 2015
    5.9
    Medium

    CVE-2015-0837

    Last Modified: 21 Nov 2024

    The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

    Published: 27 Feb 2015
    7.5
    High

    CVE-2015-1809

    Last Modified: 21 Nov 2024

    XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.

    Published: 27 Feb 2015
    4.6
    Medium

    CVE-2015-1810

    Last Modified: 12 Apr 2025

    The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the "Jenkins' own user database" setting, which allows remote attackers to gain privileges by creating a reserved name.

    Published: 27 Feb 2015
    4.2
    Medium

    CVE-2014-3591

    Last Modified: 21 Nov 2024

    Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.

    Published: 27 Feb 2015
    7.5
    High

    CVE-2015-0254

    Last Modified: 12 Apr 2025

    Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.

    Published: 27 Feb 2015
    7.5
    High

    CVE-2015-0294

    Last Modified: 21 Nov 2024

    GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.

    Published: 27 Feb 2015
    5
    Medium

    CVE-2015-0295

    Last Modified: 12 Apr 2025

    The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.

    Published: 27 Feb 2015
    5
    Medium

    CVE-2015-0886

    Last Modified: 12 Apr 2025

    Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.

    Published: 27 Feb 2015
    6.5
    Medium

    CVE-2015-1806

    Last Modified: 12 Apr 2025

    The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

    Published: 27 Feb 2015
    3.5
    Low

    CVE-2015-1807

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with certain permissions to read arbitrary files via a symlink, related to building artifacts.

    Published: 27 Feb 2015
    3.5
    Low

    CVE-2015-1808

    Last Modified: 12 Apr 2025

    Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.

    Published: 27 Feb 2015
    7.5
    High

    CVE-2015-1811

    Last Modified: 21 Nov 2024

    XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document.

    Published: 27 Feb 2015
    6.5
    Medium

    CVE-2015-2087

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.

    Published: 26 Feb 2015
    4.3
    Medium

    CVE-2015-2088

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Term Queue module before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 26 Feb 2015
    3.5
    Low

    CVE-2015-2086

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the live preview in the Panopoly Magic module before 7.x-1.17 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a pane title.

    Published: 26 Feb 2015
    6.8
    Medium

    CVE-2015-2089

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the CrossSlide jQuery (crossslide-jquery-plugin-for-wordpress) plugin 2.0.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings or conduct cross-site scripting (XSS) attacks via the (2) csj_width, (3) csj_height, (4) csj_sleep, (5) csj_fade, or (6) upload_image parameter in the thisismyurl_csj.php page to wp-admin/options-general.php.

    Published: 26 Feb 2015
    7.5
    High

    CVE-2015-2090

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php.

    Published: 26 Feb 2015
    6.8
    Medium

    CVE-2015-0633

    Last Modified: 12 Apr 2025

    The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response packets on the local network, aka Bug ID CSCuf52876.

    Published: 26 Feb 2015