CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2012-5626

    Last Modified: 21 Nov 2024

    EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.

    Published: 6 Feb 2015
    0
    Low

    CVE-2009-1193

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 6 Feb 2015
    7.8
    High

    CVE-2012-6689

    Last Modified: 12 Apr 2025

    The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.

    Published: 6 Feb 2015
    7.3
    High

    CVE-2015-8836

    Last Modified: 12 Apr 2025

    Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF block size in an ISO file, leading to a heap-based buffer overflow.

    Published: 6 Feb 2015
    4.7
    Medium

    CVE-2015-7810

    Last Modified: 21 Nov 2024

    libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files

    Published: 6 Feb 2015
    9.8
    Critical

    CVE-2012-3460

    Last Modified: 21 Nov 2024

    cumin: At installation postgresql database user created without password

    Published: 6 Feb 2015
    7.5
    High

    CVE-2017-6056

    Last Modified: 20 Apr 2025

    It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.

    Published: 6 Feb 2015
    9.8
    Critical

    CVE-2014-3579

    Last Modified: 20 Apr 2025

    XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

    Published: 5 Feb 2015
    4.3
    Medium

    CVE-2014-8161

    Last Modified: 21 Nov 2024

    PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.

    Published: 5 Feb 2015
    4.6
    Medium

    CVE-2015-0247

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.

    Published: 5 Feb 2015
    9.8
    Critical

    CVE-2017-11720

    Last Modified: 20 Apr 2025

    There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.

    Published: 5 Feb 2015
    5.5
    Medium

    CVE-2017-15045

    Last Modified: 20 Apr 2025

    LAME 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4, 3.99.5, 3.98.4, 3.98.2 and 3.98 has a heap-based buffer over-read in fill_buffer in libmp3lame/util.c, related to lame_encode_buffer_sample_t in libmp3lame/lame.c, a different vulnerability than CVE-2017-9410.

    Published: 5 Feb 2015
    5.5
    Medium

    CVE-2017-15046

    Last Modified: 20 Apr 2025

    LAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend/get_audio.c, a different vulnerability than CVE-2017-9412.

    Published: 5 Feb 2015
    4.3
    Medium

    CVE-2014-8110

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Feb 2015
    7.2
    High

    CVE-2015-4036

    Last Modified: 12 Apr 2025

    Array index error in the tcm_vhost_make_tpg function in drivers/vhost/scsi.c in the Linux kernel before 4.0 might allow guest OS users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted VHOST_SCSI_SET_ENDPOINT ioctl call. NOTE: the affected function was renamed to vhost_scsi_make_tpg before the vulnerability was announced.

    Published: 5 Feb 2015
    3.3
    Low

    CVE-2017-9411

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-9100. Reason: This candidate is a duplicate of CVE-2015-9100. Notes: All CVE users should reference CVE-2015-9100 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Feb 2015
    5.5
    Medium

    CVE-2017-9412

    Last Modified: 20 Apr 2025

    The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file.

    Published: 5 Feb 2015
    9.8
    Critical

    CVE-2014-3600

    Last Modified: 20 Apr 2025

    XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

    Published: 5 Feb 2015
    7.5
    High

    CVE-2014-3612

    Last Modified: 12 Apr 2025

    The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.

    Published: 5 Feb 2015
    5.5
    Medium

    CVE-2015-9099

    Last Modified: 20 Apr 2025

    The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file with a negative sample rate.

    Published: 5 Feb 2015
    5.5
    Medium

    CVE-2015-9100

    Last Modified: 20 Apr 2025

    The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.

    Published: 5 Feb 2015
    7.5
    High

    CVE-2017-13712

    Last Modified: 20 Apr 2025

    NULL Pointer Dereference in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by triggering a NULL first argument.

    Published: 5 Feb 2015
    5.5
    Medium

    CVE-2017-15018

    Last Modified: 20 Apr 2025

    LAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handling a malformed file in k_34_4 in vbrquantize.c.

    Published: 5 Feb 2015
    7.8
    High

    CVE-2017-15019

    Last Modified: 20 Apr 2025

    LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call.

    Published: 5 Feb 2015
    7.8
    High

    CVE-2017-8419

    Last Modified: 20 Apr 2025

    LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of service (stack-based buffer overflow or heap-based buffer overflow) or possibly have unspecified other impact via a crafted file, as demonstrated by mishandling of num_channels.

    Published: 5 Feb 2015
    3.3
    Low

    CVE-2017-9410

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-9101. Reason: This candidate is a duplicate of CVE-2015-9101. Notes: All CVE users should reference CVE-2015-9101 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Feb 2015
    4.3
    Medium

    CVE-2014-9562

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in display_dialog.php in M2 OptimalSite 0.1 and 2.4 allows remote attackers to inject arbitrary web script or HTML via the image parameter.

    Published: 4 Feb 2015
    4
    Medium

    CVE-2014-9049

    Last Modified: 12 Apr 2025

    The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to obtain all valid session IDs via an unspecified API method.

    Published: 4 Feb 2015
    4.3
    Medium

    CVE-2014-5341

    Last Modified: 12 Apr 2025

    The SFTP external storage driver (files_external) in ownCloud Server before 6.0.5 validates the RSA Host key after login, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 4 Feb 2015
    6.8
    Medium

    CVE-2014-9041

    Last Modified: 12 Apr 2025

    The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 does not validate CSRF tokens, which allow remote attackers to conduct CSRF attacks.

    Published: 4 Feb 2015
    3.5
    Low

    CVE-2014-9042

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the import functionality in the bookmarks application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote authenticated users to inject arbitrary web script or HTML by importing a link with an unspecified protocol. NOTE: this can be leveraged by remote attackers using CVE-2014-9041.

    Published: 4 Feb 2015
    5
    Medium

    CVE-2014-9043

    Last Modified: 12 Apr 2025

    The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to bypass authentication via a null byte in the password and a valid user name, which triggers an unauthenticated bind.

    Published: 4 Feb 2015
    5
    Medium

    CVE-2014-9044

    Last Modified: 12 Apr 2025

    Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatenated file, which allows remote attackers to obtain sensitive information via a brute force attack.

    Published: 4 Feb 2015
    5
    Medium

    CVE-2014-9045

    Last Modified: 12 Apr 2025

    The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass intended authentication requirements via a crafted password.

    Published: 4 Feb 2015
    5
    Medium

    CVE-2014-9046

    Last Modified: 12 Apr 2025

    The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files via a file:// protocol.

    Published: 4 Feb 2015
    4.3
    Medium

    CVE-2014-9047

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the preview system in ownCloud 6.x before 6.0.6 and 7.x before 7.0.3 allow remote attackers to read arbitrary files via unknown vectors.

    Published: 4 Feb 2015
    5
    Medium

    CVE-2014-9048

    Last Modified: 12 Apr 2025

    The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote attackers to bypass the password-protection for shared files via the API.

    Published: 4 Feb 2015
    6.5
    Medium

    CVE-2015-1481

    Last Modified: 12 Apr 2025

    Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account.

    Published: 4 Feb 2015
    5
    Medium

    CVE-2015-1482

    Last Modified: 12 Apr 2025

    Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/.

    Published: 4 Feb 2015
    4
    Medium

    CVE-2015-1480

    Last Modified: 12 Apr 2025

    ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a direct request to (2) swf/flashreport.swf, (3) reports/flash/details.jsp, or (4) reports/CreateReportTable.jsp.

    Published: 4 Feb 2015
    6.8
    Medium

    CVE-2014-9331

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to STATE_ID/1417736606982/roleMgmt.do.

    Published: 4 Feb 2015
    4.3
    Medium

    CVE-2015-1437

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Asus RT-N10+ D1 router with firmware 2.1.1.1.70 allow remote attackers to inject arbitrary web script or HTML via the flag parameter to (1) result_of_get_changed_status.asp or (2) error_page.htm.

    Published: 4 Feb 2015
    4.3
    Medium

    CVE-2015-1478

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the view parameter to /classifieds.

    Published: 4 Feb 2015
    7.5
    High

    CVE-2014-7864

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 11400 and IT360 10.5 and earlier allow remote attackers and remote authenticated users to execute arbitrary SQL commands via the (1) customerName or (2) serverRole parameter in a standbyUpdateInCentral operation to servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.

    Published: 4 Feb 2015
    4.3
    Medium

    CVE-2015-1475

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in my little forum 2.3.3, 2.2, and 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) category parameter to forum.php or the (3) page or (4) order parameter to (a) board_entry.php or (b) forum_entry.php.

    Published: 4 Feb 2015
    7.5
    High

    CVE-2015-1476

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in xlinkerz ecommerceMajor allow remote attackers to execute arbitrary SQL commands via the (1) productbycat parameter to product.php, or (2) username or (3) password parameter to __admin/index.php.

    Published: 4 Feb 2015
    7.5
    High

    CVE-2015-1477

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewad task to classifieds/offerring-ads.

    Published: 4 Feb 2015
    6.5
    Medium

    CVE-2015-1479

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to execute arbitrary SQL commands via the site parameter.

    Published: 4 Feb 2015
    8.8
    High

    CVE-2014-0087

    Last Modified: 21 Nov 2024

    The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authorization and gain privileges by leveraging improper RBAC checking, related to the rbac_user_edit action.

    Published: 4 Feb 2015
    2.6
    Low

    CVE-2014-9297

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9750, CVE-2014-9751. Reason: this ID was intended for one issue, but was associated with two issues. Notes: All CVE users should consult CVE-2014-9750 and CVE-2014-9751 to identify the ID or IDs of interest. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 Feb 2015