CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2015-0070

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."

    Published: 11 Feb 2015
    4.3
    Medium

    CVE-2014-6362

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Microsoft Office 2007 SP3, 2010 SP2, and 2013 Gold and SP1 allows remote attackers to bypass the ASLR protection mechanism via a crafted document, aka "Microsoft Office Component Use After Free Vulnerability."

    Published: 11 Feb 2015
    1.9
    Low

    CVE-2015-0010

    Last Modified: 12 Apr 2025

    The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1, when the CRYPTPROTECTMEMORY_SAME_LOGON option is used, does not check an impersonation token's level, which allows local users to bypass intended decryption restrictions by leveraging a service that (1) has a named-pipe planting vulnerability or (2) uses world-readable shared memory for encrypted data, aka "CNG Security Feature Bypass Vulnerability" or MSRC ID 20707.

    Published: 11 Feb 2015
    6.9
    Medium

    CVE-2015-0012

    Last Modified: 12 Apr 2025

    Microsoft System Center Virtual Machine Manager (VMM) 2012 R2 Update Rollup 4 does not properly validate the roles of users, which allows local users to obtain server and virtual-machine administrative privileges by establishing a server session with Active Directory credentials, aka "Virtual Machine Manager Elevation of Privilege Vulnerability."

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0018

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0037, CVE-2015-0040, and CVE-2015-0066.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0019

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0020

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0021

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0027

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0035, CVE-2015-0039, CVE-2015-0052, and CVE-2015-0068.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0028

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0048.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0030

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0035

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0027, CVE-2015-0039, CVE-2015-0052, and CVE-2015-0068.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0036

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, and CVE-2015-0041.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0037

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0018, CVE-2015-0040, and CVE-2015-0066.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0038

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0042 and CVE-2015-0046.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0041

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0017, CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, and CVE-2015-0036.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0042

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0038 and CVE-2015-0046.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0043

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0044

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-8967 and CVE-2015-0050.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0045

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0053.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0046

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0038 and CVE-2015-0042.

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0050

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-8967 and CVE-2015-0044.

    Published: 11 Feb 2015
    4.3
    Medium

    CVE-2015-0051

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."

    Published: 11 Feb 2015
    9.3
    Critical

    CVE-2015-0053

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0045.

    Published: 11 Feb 2015
    4.3
    Medium

    CVE-2015-0054

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

    Published: 11 Feb 2015
    9.8
    Critical

    CVE-2015-1427

    Last Modified: 22 Apr 2026

    The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

    Published: 11 Feb 2015
    8.8
    High

    CVE-2015-1877

    Last Modified: 21 Nov 2024

    The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.

    Published: 11 Feb 2015
    4
    Medium

    CVE-2014-7853

    Last Modified: 12 Apr 2025

    The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging access to the security-domain attribute.

    Published: 11 Feb 2015
    3.5
    Low

    CVE-2014-7827

    Last Modified: 12 Apr 2025

    The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authenticated users to bypass intended access restrictions by leveraging credentials on the default domain for a role that is also on the application domain.

    Published: 11 Feb 2015
    4
    Medium

    CVE-2014-7849

    Last Modified: 12 Apr 2025

    The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.

    Published: 11 Feb 2015
    4.6
    Medium

    CVE-2015-1572

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0247.

    Published: 11 Feb 2015
    6.2
    Medium

    CVE-2023-3108

    Last Modified: 20 Nov 2025

    A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in the skcipher_recvmsg of crypto/algif_skcipher.c function. This flaw allows a local user to crash the system.

    Published: 11 Feb 2015
    5.8
    Medium

    CVE-2015-1042

    Last Modified: 12 Apr 2025

    The string_sanitize_url function in core/string_api.php in MantisBT 1.2.0a3 through 1.2.18 uses an incorrect regular expression, which allows remote attackers to conduct open redirect and phishing attacks via a URL with a ":/" (colon slash) separator in the return parameter to login_page.php, a different vulnerability than CVE-2014-6316.

    Published: 10 Feb 2015
    4.9
    Medium

    CVE-2015-1377

    Last Modified: 12 Apr 2025

    The Read Mail module in Webmin 1.720 allows local users to read arbitrary files via a symlink attack on an unspecified file.

    Published: 10 Feb 2015
    4.3
    Medium

    CVE-2015-1571

    Last Modified: 12 Apr 2025

    The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private key across different customers' installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the Fortinet_Factory certificate and private key. NOTE: FG-IR-15-002 says "The Fortinet_Factory certificate is unique to each device ... An attacker cannot therefore stage a MitM attack.

    Published: 10 Feb 2015
    7.5
    High

    CVE-2015-1169

    Last Modified: 12 Apr 2025

    Apereo Central Authentication Service (CAS) Server before 3.5.3 allows remote attackers to conduct LDAP injection attacks via a crafted username, as demonstrated by using a wildcard and a valid password to bypass LDAP authentication.

    Published: 10 Feb 2015
    4.3
    Medium

    CVE-2015-1569

    Last Modified: 12 Apr 2025

    Fortinet FortiClient 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof SSL VPN servers via a crafted certificate.

    Published: 10 Feb 2015
    4.3
    Medium

    CVE-2015-1570

    Last Modified: 12 Apr 2025

    The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.028 for iOS does not validate certificates, which makes it easier for man-in-the-middle attackers to spoof servers via a crafted certificate.

    Published: 10 Feb 2015
    2.1
    Low

    CVE-2014-8733

    Last Modified: 12 Apr 2025

    Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files under /etc/hadoop, which allows local users to obtain this password.

    Published: 10 Feb 2015
    5
    Medium

    CVE-2015-1548

    Last Modified: 12 Apr 2025

    mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read.

    Published: 10 Feb 2015
    6.8
    Medium

    CVE-2015-1432

    Last Modified: 12 Apr 2025

    The message_options function in includes/ucp/ucp_pm_options.php in phpBB before 3.0.13 does not properly validate the form key, which allows remote attackers to conduct CSRF attacks and change the full folder setting via unspecified vectors.

    Published: 10 Feb 2015
    6.8
    Medium

    CVE-2015-1559

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in administrator.php in Epignosis eFront Open Source Edition before 3.6.15.3 build 18022 allow remote attackers to hijack the authentication of administrators for requests that (1) delete modules via the delete_module parameter, (2) deactivate modules via the deactivate_module parameter, (3) activate modules via the activate_module parameter, (4) delete users via the delete_user parameter, (5) deactivate users via the deactivate_user parameter, (6) activate users via the activate_user parameter, (7) activate themes via the set_theme parameter, (8) deactivate themes via the set_theme parameter, (9) delete themes via the delete parameter, (10) deactivate events (user registration or email activation) via the deactivate_notification parameter, (11) activate events via the activate_notification parameter, (12) delete events via the delete_notification parameter, (13) deactivate language settings via the deactivate_language parameter, (14) activate language settings via the activate_language parameter, (15) delete language settings via the delete_language parameter, or (16) activate or deactivate the autologin feature for a user via a crafted maintenance request.

    Published: 10 Feb 2015
    4.3
    Medium

    CVE-2015-1431

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in includes/startup.php in phpBB before 3.0.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to "Relative Path Overwrite."

    Published: 10 Feb 2015
    6.8
    Medium

    CVE-2014-9679

    Last Modified: 12 Apr 2025

    Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via a malformed compressed raster file, which triggers a buffer overflow.

    Published: 10 Feb 2015
    2.1
    Low

    CVE-2015-1426

    Last Modified: 12 Apr 2025

    Puppet Labs Facter 1.6.0 through 2.4.0 allows local users to obtains sensitive Amazon EC2 IAM instance metadata by reading a fact for an Amazon EC2 node.

    Published: 10 Feb 2015
    7.5
    High

    CVE-2015-0226

    Last Modified: 20 Apr 2025

    Apache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks information about decryption failures when decrypting an encrypted key or message data, which makes it easier for remote attackers to recover the plaintext form of a symmetric key via a series of crafted messages. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-2487.

    Published: 10 Feb 2015
    3.6
    Low

    CVE-2015-0267

    Last Modified: 12 Apr 2025

    The Red Hat module-setup.sh script for kexec-tools, as distributed in the kexec-tools before 2.0.7-19 packages in Red Hat Enterprise Linux, allows local users to write to arbitrary files via a symlink attack on a temporary file.

    Published: 10 Feb 2015
    5
    Medium

    CVE-2015-0227

    Last Modified: 12 Apr 2025

    Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

    Published: 10 Feb 2015
    6.4
    Medium

    CVE-2015-0255

    Last Modified: 29 Aug 2025

    X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (crash) via a crafted string length value in a XkbSetGeometry request.

    Published: 10 Feb 2015
    6.8
    Medium

    CVE-2015-1568

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the GD Infinite Scroll module before 7.x-1.4 for Drupal allows remote attackers to hijack the authentication of users with the "edit gd infinite scroll settings" permission for requests that delete settings via unspecified vectors.

    Published: 9 Feb 2015