CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2015-1564

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in style-underground/search in Plain Black WebGUI 7.10.29 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field.

    Published: 9 Feb 2015
    4.3
    Medium

    CVE-2015-1566

    Last Modified: 24 Apr 2026

    Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Feb 2015
    4.3
    Medium

    CVE-2015-1565

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the online help in Hitachi Device Manager, Tiered Storage Manager, Replication Manager, and Global Link Manager before 8.1.2-00, and Compute Systems Manager before 7.6.1-08 and 8.x before 8.1.2-00, as used in Hitachi Command Suite, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Feb 2015
    4.3
    Medium

    CVE-2015-1567

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the admin page in the GD Infinite Scroll module before 7.x-1.4 for Drupal allows remote authenticated users with the "edit gd infinite scroll settings" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Feb 2015
    Unknown

    CVE-2015-0246

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-1493. Reason: This candidate is a reservation duplicate of CVE-2015-1493. Notes: All CVE users should reference CVE-2015-1493 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 Feb 2015
    3.5
    Low

    CVE-2015-1558

    Last Modified: 12 Apr 2025

    Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.

    Published: 9 Feb 2015
    4.3
    Medium

    CVE-2015-1562

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Saurus CMS 4.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to admin/user_management.php, (2) data_search parameter to /admin/profile_data.php, or (3) filter parameter to error_log.php.

    Published: 9 Feb 2015
    6.4
    Medium

    CVE-2014-0227

    Last Modified: 12 Apr 2025

    java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.

    Published: 9 Feb 2015
    6.8
    Medium

    CVE-2015-0209

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the d2i_ECPrivateKey function in crypto/ec/ec_asn1.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed Elliptic Curve (EC) private-key file that is improperly handled during import.

    Published: 9 Feb 2015
    1.9
    Low

    CVE-2015-0245

    Last Modified: 12 Apr 2025

    D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds.

    Published: 9 Feb 2015
    6.5
    Medium

    CVE-2015-2058

    Last Modified: 12 Apr 2025

    c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via a crafted JID.

    Published: 9 Feb 2015
    Unknown

    CVE-2014-8614

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2014. Notes: none

    Published: 8 Feb 2015
    Unknown

    CVE-2014-8615

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2014. Notes: none

    Published: 8 Feb 2015
    4.6
    Medium

    CVE-2013-6501

    Last Modified: 12 Apr 2025

    The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_sdl function in ext/soap/php_sdl.c.

    Published: 8 Feb 2015
    7.5
    High

    CVE-2014-9674

    Last Modified: 12 Apr 2025

    The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.

    Published: 8 Feb 2015
    5
    Medium

    CVE-2014-9675

    Last Modified: 12 Apr 2025

    bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.

    Published: 8 Feb 2015
    4.3
    Medium

    CVE-2015-0072

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFRAME element that does not trigger a redirect, and an eval of a WindowProxy object, aka "Universal XSS (UXSS)."

    Published: 7 Feb 2015
    4.3
    Medium

    CVE-2015-0871

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Mrs. Shiromuku Perl CGI shiromuku(u1)GUESTBOOK 1.62 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Feb 2015
    5
    Medium

    CVE-2015-0600

    Last Modified: 12 Apr 2025

    The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to cause a denial of service (logoff) via crafted packets, aka Bug ID CSCuq12139.

    Published: 7 Feb 2015
    5
    Medium

    CVE-2014-9203

    Last Modified: 12 Apr 2025

    Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, GE Vector DTM 1.00.0, GE SVi1000 Positioner DTM 1.00.0, GE SVI II AP Positioner DTM 2.00.1, and GE 12400 Level Transmitter DTM 1.00.0, allows remote attackers to cause a denial of service (DTM outage) via crafted packets.

    Published: 7 Feb 2015
    9
    Critical

    CVE-2015-0589

    Last Modified: 12 Apr 2025

    The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authenticated users to execute arbitrary OS commands with root privileges via unspecified fields, aka Bug ID CSCuj40460.

    Published: 7 Feb 2015
    5
    Medium

    CVE-2015-0602

    Last Modified: 12 Apr 2025

    The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by sniffing the network, aka Bug ID CSCuq12117.

    Published: 7 Feb 2015
    6.3
    Medium

    CVE-2013-5557

    Last Modified: 12 Apr 2025

    The Proxy Bypass Content Rewriter feature in the WebVPN subsystem in Cisco Adaptive Security Appliance (ASA) Software 9.1(.2) and earlier allows remote authenticated users to cause a denial of service (device crash or error-recovery event) via an HTTP request that triggers a rewrite, aka Bug ID CSCug91577.

    Published: 7 Feb 2015
    4.6
    Medium

    CVE-2015-0601

    Last Modified: 12 Apr 2025

    Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allow local users to cause a denial of service (device reload) via crafted commands, aka Bug ID CSCup92790.

    Published: 7 Feb 2015
    4.6
    Medium

    CVE-2015-0603

    Last Modified: 12 Apr 2025

    Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier use weak permissions for unspecified files, which allows local users to cause a denial of service (persistent hang or reboot) by writing to a phone's filesystem, aka Bug ID CSCup90474.

    Published: 7 Feb 2015
    5
    Medium

    CVE-2015-0604

    Last Modified: 12 Apr 2025

    The web framework on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to upload files to arbitrary locations on a phone's filesystem via crafted HTTP requests, aka Bug ID CSCup90424.

    Published: 7 Feb 2015
    4.3
    Medium

    CVE-2015-0605

    Last Modified: 12 Apr 2025

    The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 and earlier allows remote attackers to bypass intended content restrictions via a crafted e-mail attachment with uuencode encoding, aka Bug ID CSCzv54343.

    Published: 7 Feb 2015
    7.3
    High

    CVE-2015-8837

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long pathname in an ISO file.

    Published: 7 Feb 2015
    7.2
    High

    CVE-2014-9642

    Last Modified: 12 Apr 2025

    bdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted 0x0022405c IOCTL call.

    Published: 6 Feb 2015
    7.2
    High

    CVE-2014-9643

    Last Modified: 12 Apr 2025

    K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8, 0x950025ac, or 0x950025c8 IOCTL call.

    Published: 6 Feb 2015
    4.3
    Medium

    CVE-2015-1512

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in FancyFon FAMOC before 3.17.4 allow remote attackers to inject arbitrary web script or HTML via the (1) LoginForm[username] to ui/system/login or the (2) order or (3) myorgs to index.php.

    Published: 6 Feb 2015
    7.5
    High

    CVE-2015-1513

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in SIPhone Enterprise PBX allows remote attackers to execute arbitrary SQL commands via the Username.

    Published: 6 Feb 2015
    7.2
    High

    CVE-2014-9632

    Last Modified: 12 Apr 2025

    The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x830020f8 IOCTL call.

    Published: 6 Feb 2015
    7.2
    High

    CVE-2014-9641

    Last Modified: 12 Apr 2025

    The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x00222400 IOCTL call.

    Published: 6 Feb 2015
    6.9
    Medium

    CVE-2015-1305

    Last Modified: 12 Apr 2025

    McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call.

    Published: 6 Feb 2015
    7.5
    High

    CVE-2015-1442

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in views/zero_transact_user.php in the administrative backend in ZeroCMS 1.3.3, 1.3.2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the user_id parameter in a Modify Account action. NOTE: The article_id parameter to zero_view_article.php vector is already covered by CVE-2014-4034.

    Published: 6 Feb 2015
    4.3
    Medium

    CVE-2015-1444

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web administration frontend in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allow remote attackers to inject arbitrary web script or HTML via the (1) conntrack.cgi, (2) index.cgi, (3) log_syslog.cgi, (4) problems.cgi, (5) status.cgi, (6) status_network.cgi, or (7) status_system.cgi script in admin/.

    Published: 6 Feb 2015
    7.5
    High

    CVE-2015-1467

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) language[] or (2) type[] parameter to private/en/locale/index.

    Published: 6 Feb 2015
    7.5
    High

    CVE-2015-1514

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in FancyFon FAMOC before 3.17.4 allow (1) remote attackers to execute arbitrary SQL commands via the device ID REST parameter (PATH_INFO) to /ajax.php or (2) remote authenticated users to execute arbitrary SQL commands via the order parameter to index.php.

    Published: 6 Feb 2015
    4
    Medium

    CVE-2014-9354

    Last Modified: 12 Apr 2025

    NetApp OnCommand Balance before 4.2P3 allows local users to obtain sensitive information via unspecified vectors related to cleartext storage.

    Published: 6 Feb 2015
    10
    Critical

    CVE-2014-0605

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the SaveSettings method.

    Published: 6 Feb 2015
    Unknown

    CVE-2014-0606

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0603. Reason: This issue was MERGED into CVE-2014-0603 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2014-0603 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Feb 2015
    10
    Critical

    CVE-2014-0603

    Last Modified: 12 Apr 2025

    The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (memory corruption) and execute arbitrary code via vectors related to the (1) GetGlobalSettings or (2) GetSiteProperties3 methods, which triggers a dereference of an arbitrary memory address. NOTE: this issue was MERGED with CVE-2014-0606 because it is the same type of vulnerability, affecting the same set of versions, and discovered by the same researcher.

    Published: 6 Feb 2015
    10
    Critical

    CVE-2014-0604

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the StartLog method.

    Published: 6 Feb 2015
    10
    Critical

    CVE-2014-9353

    Last Modified: 12 Apr 2025

    NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vectors.

    Published: 6 Feb 2015
    6.9
    Medium

    CVE-2014-5332

    Last Modified: 12 Apr 2025

    Race condition in NVMap in NVIDIA Tegra Linux Kernel 3.10 allows local users to gain privileges via a crafted NVMAP_IOC_CREATE IOCTL call, which triggers a use-after-free error, as demonstrated by using a race condition to escape the Chrome sandbox.

    Published: 6 Feb 2015
    4.7
    Medium

    CVE-2013-4235

    Last Modified: 21 Nov 2024

    shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees

    Published: 6 Feb 2015
    7.3
    High

    CVE-2013-4245

    Last Modified: 21 Nov 2024

    Orca has arbitrary code execution due to insecure Python module load

    Published: 6 Feb 2015
    7.1
    High

    CVE-2013-4374

    Last Modified: 21 Nov 2024

    An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files.

    Published: 6 Feb 2015
    7.5
    High

    CVE-2015-2785

    Last Modified: 12 Apr 2025

    The GIF encoder in Byzanz allows remote attackers to cause a denial of service (out-of-bounds heap write and crash) or possibly execute arbitrary code via a crafted Byzanz debug data recording (ByzanzRecording file) to the byzanz-playback command.

    Published: 6 Feb 2015