CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2015-1380

    Last Modified: 12 Apr 2025

    jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.

    Published: 26 Jan 2015
    5
    Medium

    CVE-2015-1382

    Last Modified: 12 Apr 2025

    parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.

    Published: 26 Jan 2015
    7.5
    High

    CVE-2015-1396

    Last Modified: 21 Nov 2024

    A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.

    Published: 24 Jan 2015
    7.5
    High

    CVE-2015-2301

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted renaming of a Phar archive to the name of an existing file.

    Published: 24 Jan 2015
    7.5
    High

    CVE-2015-1379

    Last Modified: 20 Apr 2025

    The signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8 allow remote attackers to cause a denial of service (process freeze or crash).

    Published: 24 Jan 2015
    9.8
    Critical

    CVE-2015-0311

    Last Modified: 21 Apr 2026

    Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.

    Published: 23 Jan 2015
    4.3
    Medium

    CVE-2015-1176

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.

    Published: 23 Jan 2015
    2.1
    Low

    CVE-2015-1200

    Last Modified: 12 Apr 2025

    Race condition in pxz 4.999.99 Beta 3 uses weak file permissions for the output file when compressing a file before changing the permission to match the original file, which allows local users to bypass the intended access restrictions.

    Published: 23 Jan 2015
    5
    Medium

    CVE-2014-8802

    Last Modified: 12 Apr 2025

    The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

    Published: 23 Jan 2015
    4.3
    Medium

    CVE-2015-1180

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the pageId parameter to networktile/bullet.

    Published: 23 Jan 2015
    4.3
    Medium

    CVE-2015-1347

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

    Published: 23 Jan 2015
    7.8
    High

    CVE-2015-9004

    Last Modified: 20 Apr 2025

    kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.

    Published: 23 Jan 2015
    7.5
    High

    CVE-2013-7422

    Last Modified: 12 Apr 2025

    Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.

    Published: 23 Jan 2015
    7.8
    High

    CVE-2015-1465

    Last Modified: 12 Apr 2025

    The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period for redirecting lookups in the absence of caching, which allows remote attackers to cause a denial of service (memory consumption or system crash) via a flood of packets.

    Published: 23 Jan 2015
    5
    Medium

    CVE-2015-1309

    Last Modified: 12 Apr 2025

    XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATT_DISPLAY_XMLSTRING_REMOTE, aka SAP Note 2016638.

    Published: 22 Jan 2015
    10
    Critical

    CVE-2015-1311

    Last Modified: 12 Apr 2025

    The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Jan 2015
    7.5
    High

    CVE-2015-1312

    Last Modified: 12 Apr 2025

    The Dealer Portal in SAP ERP does not properly restrict access, which allows remote attackers to obtain sensitive information, gain privileges, and possibly have other unspecified impact via unknown vectors, aka SAP Note 2000401. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Jan 2015
    7.5
    High

    CVE-2015-1310

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in SAP Adaptive Server Enterprise (Sybase ASE) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Note 2113333. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Jan 2015
    4.3
    Medium

    CVE-2015-1175

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in blocklayered-ajax.php in the blocklayered module in PrestaShop 1.6.0.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the layered_price_slider parameter.

    Published: 22 Jan 2015
    5
    Medium

    CVE-2015-1306

    Last Modified: 12 Apr 2025

    The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 22 Jan 2015
    6.8
    Medium

    CVE-2014-8008

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authenticated users to read arbitrary files via a full pathname in an API command, aka Bug ID CSCur49414.

    Published: 22 Jan 2015
    9
    Critical

    CVE-2015-0925

    Last Modified: 12 Apr 2025

    The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperly handled by a subprocess reached through a named pipe, as demonstrated by a UNC share pathname.

    Published: 22 Jan 2015
    7.8
    High

    CVE-2015-0310

    Last Modified: 21 Apr 2026

    Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown vectors, as exploited in the wild in January 2015.

    Published: 22 Jan 2015
    3.3
    Low

    CVE-2015-0238

    Last Modified: 20 Apr 2025

    selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege escalation attack.

    Published: 22 Jan 2015
    10
    Critical

    CVE-2015-1421

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggering an INIT collision that leads to improper handling of shared-key data.

    Published: 22 Jan 2015
    3.5
    Low

    CVE-2015-0236

    Last Modified: 12 Apr 2025

    libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.

    Published: 22 Jan 2015
    4.3
    Medium

    CVE-2015-0431

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0 6.3.1, 6.3.2, 6.3.4, and 6.3.5 allows remote attackers to affect integrity via unknown vectors related to UI Infrastructure.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2015-0422

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, and 6.3.5 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Infrastructure.

    Published: 21 Jan 2015
    3.3
    Low

    CVE-2015-0429

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect integrity and availability via vectors related to RPC Utility.

    Published: 21 Jan 2015
    1.9
    Low

    CVE-2015-0430

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect confidentiality via vectors related to RPC Utility.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2015-0420

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Forms component in Oracle Fusion Middleware 11.1.1.7 and 11.1.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Forms Services.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2015-0414

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle SOA Suite component in Oracle Fusion Middleware 11.1.1.7 and 12.1.3.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Fabric Layer.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2015-0415

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Session Management.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2015-0416

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Roles & Privileges.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2015-0417

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Portal Framework, a different vulnerability than CVE-2015-0388.

    Published: 21 Jan 2015
    2.1
    Low

    CVE-2015-0418

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0377.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2015-0419

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Portal Framework, a different vulnerability than CVE-2013-1510.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2015-0424

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Integrated Lights Out Manager (ILOM) component in Oracle Sun Systems Products Suite ILOM prior to 3.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to IPMI.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2015-0425

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Enterprise Asset Management component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Siebel Core - Unix/Windows.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2015-0426

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.3 and 12.1.0.4 allows remote attackers to affect confidentiality via unknown vectors related to UI Framework.

    Published: 21 Jan 2015
    3.2
    Low

    CVE-2015-0427

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 4.3.20 allows local users to affect integrity and availability via vectors related to VMSVGA virtual graphics device, a different vulnerability than CVE-2014-6588, CVE-2014-6589, CVE-2014-6590, and CVE-2014-6595.

    Published: 21 Jan 2015
    4.9
    Medium

    CVE-2015-0428

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Resource Control.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2015-0434

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to affect confidentiality via vectors related to Integration with OAM.

    Published: 21 Jan 2015
    6.8
    Medium

    CVE-2015-0435

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, and 6.3.5 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2015-0436

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect confidentiality via unknown vectors related to Login.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2013-6892

    Last Modified: 12 Apr 2025

    WebSVN 2.3.3 allows remote authenticated users to read arbitrary files via a symlink attack in a commit.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2014-6599

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel Core - Common Components component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Email.

    Published: 21 Jan 2015
    7.6
    High

    CVE-2014-6598

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Communications Diameter Signaling Router component in Oracle Communications Applications 3.x, 4.x, and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Signaling - DPI.

    Published: 21 Jan 2015
    4.9
    Medium

    CVE-2014-6600

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to File System, a different vulnerability than CVE-2014-6570 and CVE-2015-0397.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2015-0363

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel Core EAI component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect availability via unknown vectors related to Integration Business Services.

    Published: 21 Jan 2015