CVE Feed

    Dashboard / CVE

    8.5
    High

    CVE-2015-1499

    Last Modified: 12 Apr 2025

    The ActiveMQ Broker in Samsung Security Manager (SSM) before 1.31 allows remote attackers to delete arbitrary files, and consequently cause a denial of service, via a DELETE request.

    Published: 16 Feb 2015
    4
    Medium

    CVE-2015-0260

    Last Modified: 12 Apr 2025

    RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method.

    Published: 16 Feb 2015
    4.3
    Medium

    CVE-2015-1435

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in my little forum before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the back parameter to index.php.

    Published: 16 Feb 2015
    6.5
    Medium

    CVE-2015-1434

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.php.

    Published: 16 Feb 2015
    6.8
    Medium

    CVE-2015-1495

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in Motorola Scanner SDK allow remote attackers to execute arbitrary code via a crafted string to the Open method in (1) IOPOSScanner.ocx or (2) IOPOSScale.ocx.

    Published: 16 Feb 2015
    7.2
    High

    CVE-2015-1496

    Last Modified: 12 Apr 2025

    Motorola Scanner SDK uses weak permissions for (1) CoreScanner.exe, (2) rsmdriverproviderservice.exe, and (3) ScannerService.exe, which allows local users to gain privileges via unspecified vectors.

    Published: 16 Feb 2015
    10
    Critical

    CVE-2015-1497

    Last Modified: 12 Apr 2025

    radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execute arbitrary commands via a crafted request to TCP port 3465.

    Published: 16 Feb 2015
    6.8
    Medium

    CVE-2015-1501

    Last Modified: 12 Apr 2025

    The factory.loadExtensionFactory function in TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to execute arbitrary code via a UNC path to a crafted binary.

    Published: 16 Feb 2015
    4
    Medium

    CVE-2015-1613

    Last Modified: 12 Apr 2025

    RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method.

    Published: 16 Feb 2015
    4
    Medium

    CVE-2015-1608

    Last Modified: 12 Apr 2025

    Topline Opportunity Form (aka XLS Opp form) before 2015-02-15 does not properly restrict access to database-connection strings, which allows attackers to read the cleartext version of sensitive credential and e-mail address information via unspecified vectors.

    Published: 16 Feb 2015
    4.3
    Medium

    CVE-2014-6113

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Reports component in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Feb 2015
    4.3
    Medium

    CVE-2014-6137

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Feb 2015
    8.8
    High

    CVE-2015-0242

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a floating point number with a large precision, as demonstrated by using the to_char function.

    Published: 16 Feb 2015
    8.8
    High

    CVE-2015-0243

    Last Modified: 21 Nov 2024

    Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

    Published: 16 Feb 2015
    9.8
    Critical

    CVE-2015-0244

    Last Modified: 21 Nov 2024

    PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.

    Published: 16 Feb 2015
    10
    Critical

    CVE-2015-1474

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the GraphicBuffer::unflatten function in platform/frameworks/native/libs/ui/GraphicBuffer.cpp in Android through 5.0 allow attackers to gain privileges or cause a denial of service (memory corruption) via vectors that trigger a large number of (1) file descriptors or (2) integer values.

    Published: 16 Feb 2015
    8.8
    High

    CVE-2015-0241

    Last Modified: 21 Nov 2024

    The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric formatting template, which triggers a buffer over-read, or (2) crafted timestamp formatting template, which triggers a buffer overflow.

    Published: 16 Feb 2015
    7.1
    High

    CVE-2015-0609

    Last Modified: 12 Apr 2025

    Race condition in the Common Classification Engine (CCE) in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express Forwarding (CEF) switching, aka Bug ID CSCuj96752.

    Published: 16 Feb 2015
    5
    Medium

    CVE-2015-1574

    Last Modified: 12 Apr 2025

    The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent application crash) via a "Content-Disposition: ;" header in an e-mail message.

    Published: 15 Feb 2015
    Unknown

    CVE-2014-7196

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-7169. Reason: This candidate is a duplicate of CVE-2014-7169. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2014-7169 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Feb 2015
    5
    Medium

    CVE-2014-7883

    Last Modified: 12 Apr 2025

    HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response.

    Published: 15 Feb 2015
    1.8
    Low

    CVE-2015-0875

    Last Modified: 12 Apr 2025

    The Ogaki Kyoritsu Bank Smartphone Passbook application 1.0.0 for Android creates a log file containing input data from the user, which allows attackers to obtain sensitive information by reading a file.

    Published: 15 Feb 2015
    2.1
    Low

    CVE-2015-0519

    Last Modified: 12 Apr 2025

    The InputAccel Database (IADB) installation process in EMC Captiva Capture 7.0 before patch 25 and 7.1 before patch 13 places a cleartext InputAccel (IA) SQL password in a DAL log file, which allows local users to obtain sensitive information by reading a file.

    Published: 14 Feb 2015
    4
    Medium

    CVE-2015-0517

    Last Modified: 12 Apr 2025

    The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5 hash of an encryption passphrase in log files, which allows remote authenticated users to obtain sensitive information by reading a file.

    Published: 14 Feb 2015
    9
    Critical

    CVE-2015-0518

    Last Modified: 12 Apr 2025

    The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 allows remote authenticated users to obtain superuser privileges via an unspecified method call that modifies group permissions.

    Published: 14 Feb 2015
    1.9
    Low

    CVE-2014-6195

    Last Modified: 12 Apr 2025

    The (1) Java GUI and (2) Web GUI components in the IBM Tivoli Storage Manager (TSM) Backup-Archive client 5.4 and 5.5 before 5.5.4.4 on AIX, Linux, and Solaris; 5.4.x and 5.5.x on Windows and z/OS; 6.1 before 6.1.5.7 on z/OS; 6.1 and 6.2 before 6.2.5.2 on Windows, before 6.2.5.3 on AIX and Linux x86, and before 6.2.5.4 on Linux Z and Solaris; 6.3 before 6.3.2.1 on AIX, before 6.3.2.2 on Windows, and before 6.3.2.3 on Linux; 6.4 before 6.4.2.1; and 7.1 before 7.1.1 in IBM TSM for Mail, when the Data Protection for Lotus Domino component is used, allow local users to bypass authentication and restore a Domino database or transaction-log backup via unspecified vectors.

    Published: 14 Feb 2015
    5
    Medium

    CVE-2015-0923

    Last Modified: 12 Apr 2025

    The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference within an XML document named in the xslt parameter, related to an XML External Entity (XXE) issue.

    Published: 14 Feb 2015
    4.3
    Medium

    CVE-2014-4804

    Last Modified: 12 Apr 2025

    Curam Universal Access in IBM Curam Social Program Management 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4.5 before iFix007, 6.0.5.4 before iFix005, and 6.0.5.5 before iFix003, when SPI inclusion is enabled, allows remote attackers to obtain sensitive user data by visiting an unspecified page.

    Published: 14 Feb 2015
    4.3
    Medium

    CVE-2014-8911

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Content Navigator 2.0.0 and 2.0.1 before 2.0.1.2 FP002 IF003 and 2.0.3 before 2.0.3.2 FP002 allows remote attackers to inject arbitrary web script or HTML via the Accept-Language HTTP header.

    Published: 14 Feb 2015
    6.8
    Medium

    CVE-2015-0931

    Last Modified: 12 Apr 2025

    Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to execute arbitrary code via a crafted XSLT document, related to a "resource injection" issue.

    Published: 14 Feb 2015
    7.2
    High

    CVE-2014-6185

    Last Modified: 12 Apr 2025

    dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 does not properly restrict shared-library loading, which allows local users to gain privileges via a crafted DSO file.

    Published: 13 Feb 2015
    3.5
    Low

    CVE-2014-8909

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF29, 8.0.0.x before 8.0.0.1 CF15, and 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 13 Feb 2015
    4
    Medium

    CVE-2014-6139

    Last Modified: 12 Apr 2025

    The Search REST API in IBM Business Process Manager 8.0.1.3, 8.5.0.1, and 8.5.5.0 allows remote authenticated users to bypass intended access restrictions and perform task-instance and process-instance searches by specifying a false value for the filterByCurrentUser parameter.

    Published: 13 Feb 2015
    4.3
    Medium

    CVE-2015-0873

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlTreeBBS 2.30 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Feb 2015
    3.5
    Low

    CVE-2014-4771

    Last Modified: 12 Apr 2025

    IBM WebSphere MQ 7.0.1 before 7.0.1.13, 7.1 before 7.1.0.6, 7.5 before 7.5.0.5, and 8 before 8.0.0.1 allows remote authenticated users to cause a denial of service (queue-slot exhaustion) by leveraging PCF query privileges for a crafted query.

    Published: 13 Feb 2015
    7.8
    High

    CVE-2014-6154

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in IBM Optim Performance Manager for DB2 4.1.0.1 through 4.1.1 on Linux, UNIX, and Windows and IBM InfoSphere Optim Performance Manager for DB2 5.1 through 5.3.1 on Linux, UNIX, and Windows allows remote attackers to access arbitrary files via a .. (dot dot) in a URL.

    Published: 13 Feb 2015
    10
    Critical

    CVE-2014-8385

    Last Modified: 12 Apr 2025

    Buffer overflow on Advantech EKI-1200 gateways with firmware before 1.63 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 13 Feb 2015
    5
    Medium

    CVE-2014-4781

    Last Modified: 12 Apr 2025

    The alert module in IBM InfoSphere BigInsights 2.1.2 and 3.x before 3.0.0.2 allows remote attackers to obtain sensitive Alert management-services API information via a network-tracing attack.

    Published: 13 Feb 2015
    3.5
    Low

    CVE-2014-4803

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in the Universal Access implementation in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix007, and 6.0.5 before 6.0.5.5 iFix003, when WebSphere Application Server is not used, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via an unspecified parameter.

    Published: 13 Feb 2015
    6.9
    Medium

    CVE-2014-4813

    Last Modified: 12 Apr 2025

    Race condition in the client in IBM Tivoli Storage Manager (TSM) 5.4.0.0 through 5.4.3.6, 5.5.0.0 through 5.5.4.3, 6.1.0.0 through 6.1.5.6, 6.2 before 6.2.5.4, 6.3 before 6.3.2.3, 6.4 before 6.4.2.1, and 7.1 before 7.1.1 on UNIX and Linux allows local users to obtain root privileges via unspecified vectors.

    Published: 13 Feb 2015
    7.1
    High

    CVE-2015-0593

    Last Modified: 12 Apr 2025

    The Zone-Based Firewall implementation in Cisco IOS 12.4(122)T and earlier does not properly manage session-object structures, which allows remote attackers to cause a denial of service (device reload) via crafted network traffic, aka Bug ID CSCul65003.

    Published: 13 Feb 2015
    5.5
    Medium

    CVE-2015-1607

    Last Modified: 21 Nov 2024

    kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges."

    Published: 13 Feb 2015
    5
    Medium

    CVE-2015-1593

    Last Modified: 12 Apr 2025

    The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift operations, which makes it easier for attackers to bypass the ASLR protection mechanism by predicting the address of the top of the stack, related to the randomize_stack_top function in fs/binfmt_elf.c and the stack_maxrandom_size function in arch/x86/mm/mmap.c.

    Published: 13 Feb 2015
    5.5
    Medium

    CVE-2015-1606

    Last Modified: 21 Nov 2024

    The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a crafted keyring file.

    Published: 13 Feb 2015
    8.1
    High

    CVE-2015-8982

    Last Modified: 20 Apr 2025

    Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc6) before 2.21 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.

    Published: 13 Feb 2015
    5.4
    Medium

    CVE-2016-2100

    Last Modified: 12 Apr 2025

    Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permission.

    Published: 13 Feb 2015
    7.5
    High

    CVE-2015-1471

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to the default URI.

    Published: 12 Feb 2015
    6.4
    Medium

    CVE-2014-9512

    Last Modified: 12 Apr 2025

    rsync 3.1.1 allows remote attackers to write to arbitrary files via a symlink attack on a file in the synchronization path.

    Published: 12 Feb 2015
    6.8
    Medium

    CVE-2014-2152

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the INSERT page in Cisco Prime Infrastructure (PI) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun21868.

    Published: 12 Feb 2015
    4.3
    Medium

    CVE-2014-2147

    Last Modified: 12 Apr 2025

    The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuj42444.

    Published: 12 Feb 2015