CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2015-1349

    Last Modified: 12 Apr 2025

    named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.

    Published: 19 Feb 2015
    2.1
    Low

    CVE-2014-6147

    Last Modified: 12 Apr 2025

    IBM Flex System Manager (FSM) 1.1.x.x, 1.2.0.x, 1.2.1.x, 1.3.0.0, 1.3.1.0, and 1.3.2.0 allows local users to obtain sensitive information, and consequently gain privileges or conduct impersonation attacks, via unspecified vectors.

    Published: 19 Feb 2015
    7.1
    High

    CVE-2015-0622

    Last Modified: 12 Apr 2025

    The Wireless Intrusion Detection (aka WIDS) functionality on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service (device outage) via crafted packets that are improperly handled during rendering of the Signature Events Summary page, aka Bug ID CSCus46861.

    Published: 19 Feb 2015
    4
    Medium

    CVE-2015-1881

    Last Modified: 12 Apr 2025

    OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.

    Published: 19 Feb 2015
    6.5
    Medium

    CVE-2015-8901

    Last Modified: 20 Apr 2025

    ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite loop) via a crafted MIFF file.

    Published: 19 Feb 2015
    7.5
    High

    CVE-2015-0273

    Last Modified: 12 Apr 2025

    Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier in (a) DateTimeZone data handled by the php_date_timezone_initialize_from_hash function or (b) DateTime data handled by the php_date_initialize_from_hash function.

    Published: 19 Feb 2015
    4.3
    Medium

    CVE-2015-0623

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administrator report page on Cisco Web Security Appliance (WSA) devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCus40627.

    Published: 19 Feb 2015
    5
    Medium

    CVE-2015-1816

    Last Modified: 12 Apr 2025

    Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.

    Published: 19 Feb 2015
    4.7
    Medium

    CVE-2015-2687

    Last Modified: 20 Apr 2025

    OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.

    Published: 19 Feb 2015
    6.5
    Medium

    CVE-2015-8902

    Last Modified: 20 Apr 2025

    The ReadBlobByte function in coders/pdb.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite loop) via a crafted PDB file.

    Published: 19 Feb 2015
    4
    Medium

    CVE-2014-9684

    Last Modified: 12 Apr 2025

    OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a different vulnerability than CVE-2015-1881.

    Published: 19 Feb 2015
    4.3
    Medium

    CVE-2015-0626

    Last Modified: 12 Apr 2025

    The SOAP interface in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to obtain access to system-management tools via crafted Challenge SOAP calls, aka Bug ID CSCuc38114.

    Published: 19 Feb 2015
    6.9
    Medium

    CVE-2015-2666

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing a crafted microcode header and leveraging root privileges for write access to the initrd.

    Published: 19 Feb 2015
    5.5
    Medium

    CVE-2015-8900

    Last Modified: 20 Apr 2025

    The ReadHDRImage function in coders/hdr.c in ImageMagick 6.x and 7.x allows remote attackers to cause a denial of service (infinite loop) via a crafted HDR file.

    Published: 19 Feb 2015
    6.5
    Medium

    CVE-2015-8903

    Last Modified: 20 Apr 2025

    The ReadVICARImage function in coders/vicar.c in ImageMagick 6.x before 6.9.0-5 Beta allows remote attackers to cause a denial of service (infinite loop) via a crafted VICAR file.

    Published: 19 Feb 2015
    2.1
    Low

    CVE-2015-1355

    Last Modified: 12 Apr 2025

    Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.

    Published: 18 Feb 2015
    5
    Medium

    CVE-2015-1358

    Last Modified: 12 Apr 2025

    The remote-management module in the (1) Multi Panels, (2) Comfort Panels, and (3) RT Advanced functionality in Siemens SIMATIC WinCC (TIA Portal) before 13 SP1 and in the (4) panels and (5) runtime functionality in SIMATIC WinCC flexible before 2008 SP3 Up7 does not properly encrypt credentials in transit, which makes it easier for remote attackers to determine cleartext credentials by sniffing the network and conducting a decryption attack.

    Published: 18 Feb 2015
    4.3
    Medium

    CVE-2015-0108

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1 through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and certain other products, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-0104, CVE-2015-0107, and CVE-2015-0109.

    Published: 18 Feb 2015
    3.5
    Low

    CVE-2015-0109

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.8, and Maximo Asset Management 7.1 through 7.1.1.8 and 7.2 for Tivoli IT Asset Management for IT and certain other products, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-0104, CVE-2015-0107, and CVE-2015-0108.

    Published: 18 Feb 2015
    5
    Medium

    CVE-2015-0617

    Last Modified: 12 Apr 2025

    Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices allow remote attackers to cause a denial of service (CPU consumption and SNMP outage) via malformed SNMP packets, aka Bug ID CSCur13393.

    Published: 18 Feb 2015
    4
    Medium

    CVE-2015-0620

    Last Modified: 12 Apr 2025

    The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entities, which allows remote authenticated users to cause a denial of service via POST requests, aka Bug ID CSCus51494.

    Published: 18 Feb 2015
    7.8
    High

    CVE-2015-0621

    Last Modified: 12 Apr 2025

    Cisco TelePresence MCU devices with software 4.5(1.45) allow remote attackers to cause a denial of service (device reload) via an unspecified series of TCP packets, aka Bug ID CSCur50347.

    Published: 18 Feb 2015
    4.4
    Medium

    CVE-2015-1356

    Last Modified: 12 Apr 2025

    Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 determines a user's privileges on the basis of project-file fields that lack integrity protection, which allows remote attackers to establish arbitrary authorization data via a modified file.

    Published: 18 Feb 2015
    5
    Medium

    CVE-2015-1827

    Last Modified: 12 Apr 2025

    The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user that belongs to a large number of groups.

    Published: 18 Feb 2015
    5.5
    Medium

    CVE-2014-0241

    Last Modified: 21 Nov 2024

    rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable

    Published: 18 Feb 2015
    6.1
    Medium

    CVE-2014-8168

    Last Modified: 20 Apr 2025

    Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.

    Published: 18 Feb 2015
    4.9
    Medium

    CVE-2015-0275

    Last Modified: 12 Apr 2025

    The ext4_zero_range function in fs/ext4/extents.c in the Linux kernel before 4.1 allows local users to cause a denial of service (BUG) via a crafted fallocate zero-range request.

    Published: 18 Feb 2015
    5
    Medium

    CVE-2015-2704

    Last Modified: 12 Apr 2025

    realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf via a newline character in an LDAP response.

    Published: 18 Feb 2015
    3.5
    Low

    CVE-2015-1619

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Secure Web Mail Client user interface in McAfee Email Gateway (MEG) 7.6.x before 7.6.3.2, 7.5.x before 75.6, 7.0.x through 7.0.5, 5.6, and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified tokens in Digest messages.

    Published: 17 Feb 2015
    3.5
    Low

    CVE-2015-1621

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Webform prepopulate block module before 7.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Feb 2015
    8.3
    High

    CVE-2014-8757

    Last Modified: 12 Apr 2025

    LG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request.

    Published: 17 Feb 2015
    4
    Medium

    CVE-2014-9466

    Last Modified: 12 Apr 2025

    Open-Xchange (OX) AppSuite and Server before 7.4.2-rev42, 7.6.0 before 7.6.0-rev36, and 7.6.1 before 7.6.1-rev14 does not properly handle directory permissions, which allows remote authenticated users to read files via unspecified vectors, related to the "folder identifier."

    Published: 17 Feb 2015
    4.3
    Medium

    CVE-2015-1494

    Last Modified: 12 Apr 2025

    The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demonstrated by the mfbfw[padding] parameter and exploited in the wild in February 2015.

    Published: 17 Feb 2015
    6.5
    Medium

    CVE-2015-1616

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated ePO users to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 Feb 2015
    3.5
    Low

    CVE-2015-1617

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Feb 2015
    4
    Medium

    CVE-2015-1618

    Last Modified: 12 Apr 2025

    The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to obtain sensitive password information via a crafted URL.

    Published: 17 Feb 2015
    2.1
    Low

    CVE-2014-6102

    Last Modified: 12 Apr 2025

    IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX008, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products do not properly handle logout actions, which allows remote attackers to bypass intended Cognos BI Direct Integration access restrictions by leveraging an unattended workstation.

    Published: 17 Feb 2015
    4
    Medium

    CVE-2014-6194

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in an unspecified web form in IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5.0 before 7.5.0.6 IFIX007, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset Management for IT and certain other products allows remote authenticated users to read arbitrary files via a .. (dot dot) in a pathname.

    Published: 17 Feb 2015
    4
    Medium

    CVE-2014-8023

    Last Modified: 12 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software 9.2(.3) and earlier, when challenge-response authentication is used, does not properly select tunnel groups, which allows remote authenticated users to bypass intended resource-access restrictions via a crafted tunnel-group parameter, aka Bug ID CSCtz48533.

    Published: 17 Feb 2015
    7.5
    High

    CVE-2014-3682

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2ResourceImpl.java in jbpm-designer 6.0.x and 6.2.x allows remote attackers to read arbitrary files and possibly have other unspecified impact by importing a crafted BPMN2 file.

    Published: 17 Feb 2015
    7.5
    High

    CVE-2014-7851

    Last Modified: 20 Apr 2025

    oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with that of another user.

    Published: 17 Feb 2015
    6.8
    Medium

    CVE-2014-8114

    Last Modified: 12 Apr 2025

    The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.

    Published: 17 Feb 2015
    3.6
    Low

    CVE-2014-9683

    Last Modified: 12 Apr 2025

    Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted filename.

    Published: 17 Feb 2015
    6.5
    Medium

    CVE-2014-8115

    Last Modified: 12 Apr 2025

    The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspecified impact via unknown vectors.

    Published: 17 Feb 2015
    7.5
    High

    CVE-2015-1315

    Last Modified: 12 Apr 2025

    Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.

    Published: 17 Feb 2015
    5
    Medium

    CVE-2015-1609

    Last Modified: 12 Apr 2025

    MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.

    Published: 17 Feb 2015
    4.3
    Medium

    CVE-2015-1436

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Easing Slider plugin before 2.2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the edit parameter in the (1) easingslider_manage_customizations or (2) easingslider_edit_sliders page to wp-admin/admin.php.

    Published: 16 Feb 2015
    10
    Critical

    CVE-2015-1498

    Last Modified: 12 Apr 2025

    Persistent Systems Radia Client Automation does not properly restrict access to certain request, which allows remote attackers to (1) enumerate user accounts via a getUsers request, (2) assign a role to a user account via an addAssigneesToRole request, (3) remove a role from a user account via a removeAssigneesFromRole request, or (4) have other unspecified impact.

    Published: 16 Feb 2015
    6.8
    Medium

    CVE-2015-1500

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in the TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to execute arbitrary code via unspecified vectors to (1) graphManager.load or (2) factory.load.

    Published: 16 Feb 2015
    9
    Critical

    CVE-2014-9375

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the LibraryFileUploadServlet servlet in Lexmark Markvision Enterprise allows remote authenticated users to write to and execute arbitrary files via a .. (dot dot) in a file path in a ZIP archive.

    Published: 16 Feb 2015