CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2015-8984

    Last Modified: 20 Apr 2025

    The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash) via a malformed pattern, which triggers an out-of-bounds read.

    Published: 26 Feb 2015
    7.5
    High

    CVE-2015-2265

    Last Modified: 12 Apr 2025

    The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.

    Published: 26 Feb 2015
    7.5
    High

    CVE-2015-3905

    Last Modified: 12 Apr 2025

    Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.

    Published: 26 Feb 2015
    4.3
    Medium

    CVE-2014-9685

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Feb 2015
    4.3
    Medium

    CVE-2015-2043

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Visualware MyConnection Server 8.2b allow remote attackers to inject arbitrary web script or HTML via the (1) bt, (2) variable, or (3) et parameter to myspeed/db/historyitem.

    Published: 25 Feb 2015
    4.3
    Medium

    CVE-2015-2082

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4 Prosoft HRMS before 8.14.330.43 allows remote attackers to inject arbitrary web script or HTML via the txtUserID parameter.

    Published: 25 Feb 2015
    6.8
    Medium

    CVE-2015-2083

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Ilch CMS allows remote attackers to hijack the authentication of administrators for requests that add a value to a profile field via a profilefields request to admin.php.

    Published: 25 Feb 2015
    6.8
    Medium

    CVE-2015-2084

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the image_file parameter in an edit action in the cnss_social_icon_add page to wp-admin/admin.php.

    Published: 25 Feb 2015
    2.6
    Low

    CVE-2015-0820

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbox protection mechanism via a crafted web site.

    Published: 25 Feb 2015
    6.9
    Medium

    CVE-2015-0833

    Last Modified: 12 Apr 2025

    Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 on Windows, when the Maintenance Service is not used, allow local users to gain privileges via a Trojan horse DLL in (1) the current working directory or (2) a temporary directory, as demonstrated by bcrypt.dll.

    Published: 25 Feb 2015
    4.3
    Medium

    CVE-2015-1796

    Last Modified: 12 Apr 2025

    The PKIX trust engines in Shibboleth Identity Provider before 2.4.4 and OpenSAML Java (OpenSAML-J) before 2.6.5 trust candidate X.509 credentials when no trusted names are available for the entityID, which allows remote attackers to impersonate an entity via a certificate issued by a shibmd:KeyAuthority trust anchor.

    Published: 25 Feb 2015
    5
    Medium

    CVE-2015-2077

    Last Modified: 12 Apr 2025

    The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio for Windows, Atom Security, Inc. StaffCop 5.8, and other products, uses the same X.509 certificate private key for a root CA certificate across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging knowledge of this key, as originally reported for Superfish VisualDiscovery on certain Lenovo Notebook laptop products.

    Published: 24 Feb 2015
    5
    Medium

    CVE-2015-2078

    Last Modified: 12 Apr 2025

    The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio for Windows, Atom Security, Inc. StaffCop 5.8, and other products, does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers, a different vulnerability than CVE-2015-2077.

    Published: 24 Feb 2015
    5
    Medium

    CVE-2014-6115

    Last Modified: 12 Apr 2025

    IBM Rational Insight 1.1.1.5 allows remote attackers to bypass authentication and obtain sensitive information via a crafted request to a Jazz Reporting Service (JRS) report URL.

    Published: 24 Feb 2015
    2.1
    Low

    CVE-2014-4818

    Last Modified: 12 Apr 2025

    dsmtca in the client in IBM Tivoli Storage Manager (TSM) 5.4.x, 5.5.x, 6.x before 6.4.3, and 7.1.x before 7.1.2 allows local users to discover the backup/restore encryption-key password via unspecified vectors.

    Published: 24 Feb 2015
    5
    Medium

    CVE-2014-9282

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Speed Root Explorer application before 3.2 for Android and the Speed Explorer application before 2.2 for Android allows remote attackers to write to arbitrary files via a crafted filename.

    Published: 24 Feb 2015
    7.5
    High

    CVE-2015-2066

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in DLGuard 4.5 allows remote attackers to execute arbitrary SQL commands via the c parameter to index.php.

    Published: 24 Feb 2015
    4.3
    Medium

    CVE-2015-2068

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.

    Published: 24 Feb 2015
    4.3
    Medium

    CVE-2015-2069

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports page to wp-admin/admin.php.

    Published: 24 Feb 2015
    4.3
    Medium

    CVE-2015-2064

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in DLGuard 5, 4.6, and 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) c, or (3) redirect parameter to index.php or (4) search field (searchTerm parameter) in the main page.

    Published: 24 Feb 2015
    7.5
    High

    CVE-2015-2065

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin before 2.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the vid parameter in a rss action to wp-admin/admin-ajax.php.

    Published: 24 Feb 2015
    5
    Medium

    CVE-2015-2067

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 24 Feb 2015
    7.5
    High

    CVE-2015-2070

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitrary SQL commands via the catId parameter to cm/blogrss/feed.

    Published: 24 Feb 2015
    4
    Medium

    CVE-2015-2071

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the filepath parameter.

    Published: 24 Feb 2015
    4
    Medium

    CVE-2014-8487

    Last Modified: 12 Apr 2025

    Kony Management (aka Enterprise Mobile Management or EMM) 1.2 and earlier allows remote authenticated users to read (1) arbitrary messages via the messageId parameter to selfservice/managedevice/getMessageBody or (2) requests via the requestId parameter to selfservice/devicemgmt/getDeviceInfoTab.htm.

    Published: 24 Feb 2015
    6.8
    Medium

    CVE-2015-0555

    Last Modified: 12 Apr 2025

    Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrary code via a long string in the first argument to the (1) ReadConfigValue or (2) WriteConfigValue function.

    Published: 24 Feb 2015
    7.5
    High

    CVE-2015-1605

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Dell ScriptLogic Asset Manager (aka Quest Workspace Asset Manager) before 9.5 allow remote attackers to execute arbitrary SQL commands via unspecified vectors to (1) GetClientPackage.aspx or (2) GetProcessedPackage.aspx.

    Published: 24 Feb 2015
    4.3
    Medium

    CVE-2015-0822

    Last Modified: 12 Apr 2025

    The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to read arbitrary files via crafted JavaScript code.

    Published: 24 Feb 2015
    6.8
    Medium

    CVE-2015-0829

    Last Modified: 12 Apr 2025

    Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.

    Published: 24 Feb 2015
    7.5
    High

    CVE-2015-0823

    Last Modified: 12 Apr 2025

    Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic Developer Console information or possibly have unspecified other impact by leveraging incorrect macro expansion, related to the ots::ots_gasp_parse function.

    Published: 24 Feb 2015
    5
    Medium

    CVE-2015-0824

    Last Modified: 12 Apr 2025

    The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of service (out-of-bounds write of zero values, and application crash) via vectors that trigger use of DrawTarget and the Cairo library for image drawing.

    Published: 24 Feb 2015
    6.8
    Medium

    CVE-2015-0826

    Last Modified: 12 Apr 2025

    The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read of heap memory) via a crafted Cascading Style Sheets (CSS) token sequence that triggers a restyle or reflow operation.

    Published: 24 Feb 2015
    5
    Medium

    CVE-2015-0830

    Last Modified: 12 Apr 2025

    The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation log, which allows remote attackers to cause a denial of service (application crash) via crafted WebGL content.

    Published: 24 Feb 2015
    6.8
    Medium

    CVE-2015-0831

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.

    Published: 24 Feb 2015
    7.5
    High

    CVE-2015-0836

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 24 Feb 2015
    4.3
    Medium

    CVE-2015-0819

    Last Modified: 12 Apr 2025

    The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.

    Published: 24 Feb 2015
    6.8
    Medium

    CVE-2015-0821

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions.

    Published: 24 Feb 2015
    4.3
    Medium

    CVE-2015-0825

    Last Modified: 12 Apr 2025

    Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory allocation during playback.

    Published: 24 Feb 2015
    4.3
    Medium

    CVE-2015-0827

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to obtain sensitive information from uninitialized process memory via a malformed SVG graphic.

    Published: 24 Feb 2015
    6.8
    Medium

    CVE-2015-0828

    Last Modified: 12 Apr 2025

    Double free vulnerability in the nsXMLHttpRequest::GetResponse function in Mozilla Firefox before 36.0, when a nonstandard memory allocator is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted JavaScript code that makes an XMLHttpRequest call with zero bytes of data.

    Published: 24 Feb 2015
    5
    Medium

    CVE-2015-0832

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.

    Published: 24 Feb 2015
    4.3
    Medium

    CVE-2015-0834

    Last Modified: 12 Apr 2025

    The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

    Published: 24 Feb 2015
    7.5
    High

    CVE-2015-0835

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 24 Feb 2015
    7.5
    High

    CVE-2015-2080

    Last Modified: 12 Apr 2025

    The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.

    Published: 24 Feb 2015
    8.8
    High

    CVE-2015-2051

    Last Modified: 22 Apr 2026

    The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

    Published: 23 Feb 2015
    9
    Critical

    CVE-2015-2049

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.

    Published: 23 Feb 2015
    10
    Critical

    CVE-2015-2050

    Last Modified: 12 Apr 2025

    D-Link DAP-1320 Rev Ax with firmware before 1.21b05 allows attackers to execute arbitrary commands via unspecified vectors.

    Published: 23 Feb 2015
    2.6
    Low

    CVE-2015-2047

    Last Modified: 12 Apr 2025

    The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.18, when configured for the frontend, allows remote attackers to bypass authentication via a password that is casted to an empty value.

    Published: 23 Feb 2015
    5
    Medium

    CVE-2015-1589

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in arCHMage 0.2.4 allows remote attackers to write to arbitrary files via a .. (dot dot) in a CHM file.

    Published: 23 Feb 2015
    6.8
    Medium

    CVE-2015-2048

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 23 Feb 2015