7.5
    High

    CVE-2015-7235

    Last Modified: 15 Sept 2015

    Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a dex_reservations_calendar_load2 action or (2) dex_item parameter in a dex_reservations_check_posted_data action in a request to the default URI.

    Source:i0akiN SEC-LABORATORY
    Published:17 Sept 2015
    5
    Medium

    CVE-2015-7214

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.

    Published:16 Dec 2015
    9.3
    Critical

    CVE-2015-7112

    Last Modified: 28 Jan 2016

    The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2015-7111.

    Source:Google Security Research
    Published:11 Dec 2015
    6.9
    Medium

    CVE-2015-7110

    Last Modified: 28 Jan 2016

    The Disk Images component in Apple OS X before 10.11.2 and tvOS before 9.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted disk image.

    Source:Google Security Research
    Published:11 Dec 2015
    7.2
    High

    CVE-2015-7108

    Last Modified: 28 Jan 2016

    The Bluetooth HCI interface in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Source:Google Security Research
    Published:11 Dec 2015
    7.2
    High

    CVE-2015-7106

    Last Modified: 28 Jan 2016

    The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Source:Google Security Research
    Published:11 Dec 2015
    7.2
    High

    CVE-2015-7084

    Last Modified: 28 Jan 2016

    The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7083.

    Source:Google Security Research
    Published:11 Dec 2015
    7.2
    High

    CVE-2015-7083

    Last Modified: 28 Jan 2016

    The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-7084.

    Source:Google Security Research
    Published:11 Dec 2015
    7.2
    High

    CVE-2015-7078

    Last Modified: 28 Jan 2016

    Use-after-free vulnerability in Hypervisor in Apple OS X before 10.11.2 allows local users to gain privileges via vectors involving VM objects.

    Source:Google Security Research
    Published:11 Dec 2015
    7.2
    High

    CVE-2015-7077

    Last Modified: 28 Jan 2016

    The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (out-of-bounds memory access) via unspecified vectors.

    Source:Google Security Research
    Published:11 Dec 2015
    7.8
    High

    CVE-2015-7068

    Last Modified: 28 Jan 2016

    IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an app that provides an unspecified userclient type.

    Source:Google Security Research
    Published:11 Dec 2015
    7.2
    High

    CVE-2015-7047

    Last Modified: 28 Jan 2016

    The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges via a crafted mach message that is misparsed.

    Source:Google Security Research
    Published:11 Dec 2015
    6.8
    Medium

    CVE-2015-7039

    Last Modified: 9 Dec 2015

    Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vulnerability than CVE-2015-7038.

    Source:Maksymilian Arciemowicz
    Published:11 Dec 2015
    7.5
    High

    CVE-2015-7007

    Last Modified: 26 Oct 2015

    Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement for AppleScript execution via unspecified vectors.

    Source:Metasploit
    Published:23 Oct 2015
    6.8
    Medium

    CVE-2015-6996

    Last Modified: 28 Jan 2016

    IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:23 Oct 2015
    6.8
    Medium

    CVE-2015-6995

    Last Modified: 28 Jan 2016

    The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:23 Oct 2015
    6.8
    Medium

    CVE-2015-6973

    Last Modified: 15 Sept 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via a crafted request to user-password.jsp, (2) add users via a crafted request to user-create.jsp, (3) edit server settings or (4) disable SSL on the server via a crafted request to server-props.jsp, or (5) add clients via a crafted request to plugins/clientcontrol/permitted-clients.jsp.

    Source:hyp3rlinx
    Published:16 Sept 2015
    4.3
    Medium

    CVE-2015-6972

    Last Modified: 15 Sept 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject arbitrary web script or HTML via the (1) groupchatName parameter to plugins/clientcontrol/create-bookmark.jsp; the (2) urlName parameter to plugins/clientcontrol/create-bookmark.jsp; the (3) hostname parameter to server-session-details.jsp; or the (4) search parameter to group-summary.jsp.

    Source:hyp3rlinx
    Published:16 Sept 2015
    9.8
    Critical

    CVE-2015-6970

    Last Modified: 1 Oct 2015

    The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.

    Source:neom22
    Published:18 Feb 2020
    6.5
    Medium

    CVE-2015-6967

    Last Modified: 11 Jul 2018

    Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.

    Source:Metasploit
    Published:16 Sept 2015
    6.8
    Medium

    CVE-2015-6965

    Last Modified: 6 Sept 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) create a field, (2) update a field, (3) delete a field, (4) create a form, (5) update a form, (6) delete a form, (7) create a template, (8) update a template, (9) delete a template, or (10) conduct cross-site scripting (XSS) attacks via a crafted request to the cfg_forms page in wp-admin/admin.php.

    Source:i0akiN SEC-LABORATORY
    Published:16 Sept 2015
    7.5
    High

    CVE-2015-6962

    Last Modified: 16 Sept 2015

    SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands via the email parameter to tkmonitor/estrutura/login/Login.actions.php.

    Source:Thierry Fernandes Faria
    Published:17 Sept 2015
    4.3
    Medium

    CVE-2015-6945

    Last Modified: 7 Sept 2015

    Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to inject arbitrary web script or HTML via the bd parameter to sys/sys/listaBD2.jsp.

    Source:hyp3rlinx
    Published:15 Sept 2015
    6.8
    Medium

    CVE-2015-6944

    Last Modified: 7 Sept 2015

    Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for requests that execute arbitrary SQL commands via the cmd parameter to sys/sys/listaBD2.jsp.

    Source:hyp3rlinx
    Published:15 Sept 2015
    7.2
    High

    CVE-2015-6923

    Last Modified: 17 Sept 2015

    The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call.

    Source:KoreLogic
    Published:21 Sept 2015
    9.8
    Critical

    CVE-2015-6922

    Last Modified: 28 Dec 2016

    Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted request to LocalAuth/setAccount.aspx or (2) write to and execute arbitrary files via a full pathname in the PathData parameter to ConfigTab/uploader.aspx.

    Source:Pedro Ribeiro
    Published:17 Feb 2020
    10
    Critical

    CVE-2015-6912

    Last Modified: 10 Sept 2015

    Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.

    Source:Han Sahin
    Published:11 Sept 2015
    7.5
    High

    CVE-2015-6911

    Last Modified: 10 Sept 2015

    SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter to watchstatus.cgi.

    Source:Han Sahin
    Published:11 Sept 2015
    5
    Medium

    CVE-2015-6908

    Last Modified: 11 Sept 2015

    The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd.

    Source:Denis Andzakovic
    Published:9 Sept 2015
    9.8
    Critical

    CVE-2015-6835

    Last Modified: 9 Sept 2015

    The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, which allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted session content.

    Source:Taoguang Chen
    Published:9 Aug 2015
    9.8
    Critical

    CVE-2015-6834

    Last Modified: 1 Dec 2016

    Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote attackers to execute arbitrary code via vectors related to (1) the Serializable interface, (2) the SplObjectStorage class, and (3) the SplDoublyLinkedList class, which are mishandled during unserialization.

    Source:Taoguang Chen
    Published:31 Jul 2015
    5
    Medium

    CVE-2015-6830

    Last Modified: 18 Aug 2025

    libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha.

    Source:Nikola Markovic
    Published:14 Sept 2015
    6.8
    Medium

    CVE-2015-6827

    Last Modified: 9 Sept 2015

    Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests that change a password via a request to signup.php.

    Source:Aryan Bayaninejad
    Published:11 Sept 2015
    7.5
    High

    CVE-2015-6811

    Last Modified: 31 Aug 2015

    SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.xml.

    Source:Dharmendra Kumar Singh
    Published:4 Sept 2015
    3.5
    Low

    CVE-2015-6810

    Last Modified: 8 Jan 2018

    Cross-site scripting (XSS) vulnerability in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) 4.x before 4.0.12.1 allows remote authenticated users to inject arbitrary web script or HTML via the event_location[address] array parameter to calendar/submit/.

    Source:snop
    Published:4 Sept 2015
    4.3
    Medium

    CVE-2015-6809

    Last Modified: 1 Sept 2015

    Multiple cross-site scripting (XSS) vulnerabilities in BEdita before 3.6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cfg[projectName] parameter to index.php/admin/saveConfig, the (2) data[stats_provider_url] parameter to index.php/areas/saveArea, or the (3) data[description] parameter to index.php/areas/saveSection.

    Source:Sébastien Morin
    Published:4 Sept 2015
    3.5
    Low

    CVE-2015-6805

    Last Modified: 21 Aug 2015

    Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the message field in a private message.

    Source:Chris Kellum
    Published:2 Sept 2015
    10
    Critical

    CVE-2015-6787

    Last Modified: 27 Oct 2016

    Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Source:Google Security Research
    Published:1 Dec 2015
    7.5
    High

    CVE-2015-6763

    Last Modified: 30 Oct 2016

    Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Source:Google Security Research
    Published:13 Oct 2015
    7.5
    High

    CVE-2015-6750

    Last Modified: 27 Oct 2016

    Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command.

    Source:Julien Ahrens
    Published:31 Aug 2015
    6.1
    Medium

    CVE-2015-6748

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.

    Published:27 Aug 2015
    7.5
    High

    CVE-2015-6668

    Last Modified: 20 Apr 2025

    The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory structure, related to an insecure direct object reference.

    Published:19 Oct 2017
    6.8
    Medium

    CVE-2015-6655

    Last Modified: 24 Aug 2015

    Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php.

    Source:Arash Khazaei
    Published:31 Aug 2015
    7.8
    High

    CVE-2015-6640

    Last Modified: 12 Apr 2025

    The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123.

    Published:6 Jan 2016
    7.8
    High

    CVE-2015-6639

    Last Modified: 2 May 2016

    The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.

    Source:laginimaineb
    Published:6 Jan 2016
    7.8
    High

    CVE-2015-6637

    Last Modified: 12 Apr 2025

    The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 25307013.

    Published:6 Jan 2016
    9.3
    Critical

    CVE-2015-6620

    Last Modified: 12 Apr 2025

    libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bugs 24123723 and 24445127.

    Published:8 Dec 2015
    9.3
    Critical

    CVE-2015-6612

    Last Modified: 12 Apr 2025

    libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges via a crafted application, aka internal bug 23540426.

    Published:3 Nov 2015
    9.3
    Critical

    CVE-2015-6606

    Last Modified: 12 Apr 2025

    The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 22301786.

    Published:6 Oct 2015
    8.8
    High

    CVE-2015-6589

    Last Modified: 28 Dec 2016

    Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary files due to insufficient restrictions in file paths to json.ashx.

    Source:Pedro Ribeiro
    Published:13 Feb 2020