CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2014-9490

    Last Modified: 12 Apr 2025

    The numtok function in lib/raven/okjson.rb in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a large exponent value in a scientific number.

    Published: 20 Jan 2015
    5
    Medium

    CVE-2014-9491

    Last Modified: 12 Apr 2025

    The devzvol_readdir function in illumos does not check the return value of a strchr call, which allows remote attackers to cause a denial of service (NULL pointer dereference and panic) via unspecified vectors.

    Published: 20 Jan 2015
    4.3
    Medium

    CVE-2014-6587

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

    Published: 20 Jan 2015
    4
    Medium

    CVE-2014-6593

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE.

    Published: 20 Jan 2015
    6.9
    Medium

    CVE-2015-0421

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the installation process.

    Published: 20 Jan 2015
    9.3
    Critical

    CVE-2015-0437

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

    Published: 20 Jan 2015
    6.8
    Medium

    CVE-2016-0505

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Options.

    Published: 20 Jan 2015
    4
    Medium

    CVE-2016-0595

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML.

    Published: 20 Jan 2015
    3.5
    Low

    CVE-2016-0598

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML.

    Published: 20 Jan 2015
    3.5
    Low

    CVE-2016-0600

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.

    Published: 20 Jan 2015
    3.5
    Low

    CVE-2016-0606

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption.

    Published: 20 Jan 2015
    10
    Critical

    CVE-2014-6601

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

    Published: 20 Jan 2015
    5.5
    Medium

    CVE-2014-9637

    Last Modified: 20 Apr 2025

    GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.

    Published: 20 Jan 2015
    5.4
    Medium

    CVE-2015-0383

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related to Hotspot.

    Published: 20 Jan 2015
    5.8
    Medium

    CVE-2015-0406

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality and availability via unknown vectors related to Deployment.

    Published: 20 Jan 2015
    5
    Medium

    CVE-2015-0407

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Swing.

    Published: 20 Jan 2015
    7.2
    High

    CVE-2015-0412

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS.

    Published: 20 Jan 2015
    1.9
    Low

    CVE-2015-0413

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u72 and 8u25 allows local users to affect integrity via unknown vectors related to Serviceability.

    Published: 20 Jan 2015
    5
    Medium

    CVE-2015-1201

    Last Modified: 12 Apr 2025

    Privoxy before 3.0.22 allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Jan 2015
    5.9
    Medium

    CVE-2015-7744

    Last Modified: 12 Apr 2025

    wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.

    Published: 20 Jan 2015
    6.5
    Medium

    CVE-2016-0502

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

    Published: 20 Jan 2015
    4
    Medium

    CVE-2016-0503

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0504.

    Published: 20 Jan 2015
    7.2
    High

    CVE-2016-0546

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that these are multiple buffer overflows in the mysqlshow tool that allow remote database servers to have unspecified impact via a long table or database name.

    Published: 20 Jan 2015
    4
    Medium

    CVE-2016-0596

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML.

    Published: 20 Jan 2015
    4
    Medium

    CVE-2016-0597

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

    Published: 20 Jan 2015
    3.5
    Low

    CVE-2016-0601

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Partition.

    Published: 20 Jan 2015
    2.8
    Low

    CVE-2016-0607

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to replication.

    Published: 20 Jan 2015
    4
    Medium

    CVE-2016-0616

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

    Published: 20 Jan 2015
    10
    Critical

    CVE-2014-6549

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

    Published: 20 Jan 2015
    2.6
    Low

    CVE-2014-6585

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6591.

    Published: 20 Jan 2015
    2.6
    Low

    CVE-2014-6591

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6585.

    Published: 20 Jan 2015
    9.3
    Critical

    CVE-2015-0395

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

    Published: 20 Jan 2015
    5
    Medium

    CVE-2015-0400

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries.

    Published: 20 Jan 2015
    6.9
    Medium

    CVE-2015-0403

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

    Published: 20 Jan 2015
    10
    Critical

    CVE-2015-0408

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.

    Published: 20 Jan 2015
    5
    Medium

    CVE-2015-0410

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.

    Published: 20 Jan 2015
    5
    Medium

    CVE-2015-1353

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it cannot be considered a security issue in the originally named product because of that product's specification. Notes: none

    Published: 20 Jan 2015
    7.5
    High

    CVE-2015-1395

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.

    Published: 20 Jan 2015
    6.8
    Medium

    CVE-2016-0504

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0503.

    Published: 20 Jan 2015
    4.3
    Medium

    CVE-2016-0594

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.21 and earlier allows remote authenticated users to affect availability via vectors related to DML.

    Published: 20 Jan 2015
    3.5
    Low

    CVE-2016-0599

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

    Published: 20 Jan 2015
    2.1
    Low

    CVE-2016-0605

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors.

    Published: 20 Jan 2015
    4
    Medium

    CVE-2016-0611

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

    Published: 20 Jan 2015
    3.5
    Low

    CVE-2016-0608

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to UDF.

    Published: 20 Jan 2015
    1.7
    Low

    CVE-2016-0609

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to privileges.

    Published: 20 Jan 2015
    3.5
    Low

    CVE-2016-0610

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.

    Published: 20 Jan 2015
    4.7
    Medium

    CVE-2015-4170

    Last Modified: 12 Apr 2025

    Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread during shutdown of a previous tty thread.

    Published: 19 Jan 2015
    5
    Medium

    CVE-2014-8152

    Last Modified: 12 Apr 2025

    Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.

    Published: 19 Jan 2015
    5
    Medium

    CVE-2015-1419

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.

    Published: 19 Jan 2015
    3.5
    Low

    CVE-2015-0862

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) message details when a message is unqueued, such as headers or arguments; (2) policy names, which are not properly handled when viewing policies; (3) details for AMQP network clients, such as the version; allow remote authenticated administrators to inject arbitrary web script or HTML via (4) user names, (5) the cluster name; or allow RabbitMQ cluster administrators to (6) modify unspecified content.

    Published: 18 Jan 2015