6.5
    Medium

    CVE-2015-4018

    Last Modified: 20 May 2015

    SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the link_ids[] parameter in an Update action in the syndication.php page to wp-admin/admin.php.

    Source:Adrián M. F.
    Published:21 May 2015
    6.8
    Medium

    CVE-2015-4010

    Last Modified: 10 Jun 2015

    Cross-site request forgery (CSRF) vulnerability in the Encrypted Contact Form plugin before 1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the iframe_url parameter in an Update Page action in the conformconf page to wp-admin/options-general.php.

    Source:Nitin Venkatesh
    Published:9 Jun 2015
    3.7
    Low

    CVE-2015-4000

    Last Modified: 27 May 2026

    The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

    Published:20 May 2015
    4.3
    Medium

    CVE-2015-3986

    Last Modified: 29 Apr 2015

    Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php.

    Source:High-Tech Bridge SA
    Published:14 May 2015
    9.8
    Critical

    CVE-2015-3934

    Last Modified: 30 Jun 2015

    Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login.

    Source:cfreer
    Published:21 Nov 2017
    9.8
    Critical

    CVE-2015-3933

    Last Modified: 24 Jun 2015

    Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.

    Source:cfreer
    Published:8 Nov 2017
    6.1
    Medium

    CVE-2015-3898

    Last Modified: 10 Oct 2016

    Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the redirectUrl parameter to (1) bonita/login.jsp or (2) bonita/loginservice.

    Source:High-Tech Bridge SA
    Published:28 Feb 2018
    5
    Medium

    CVE-2015-3897

    Last Modified: 10 Oct 2016

    Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the location parameter to bonita/portal/themeResource.

    Source:High-Tech Bridge SA
    Published:18 Jun 2015
    10
    Critical

    CVE-2015-3864

    Last Modified: 21 Dec 2016

    Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3824.

    Source:Google Security Research
    Published:1 Oct 2015
    5.5
    Medium

    CVE-2015-3839

    Last Modified: 20 Apr 2025

    The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash).

    Published:7 Aug 2017
    9.3
    Critical

    CVE-2015-3837

    Last Modified: 12 Apr 2025

    The OpenSSLX509Certificate class in org/conscrypt/OpenSSLX509Certificate.java in Android before 5.1.1 LMY48I improperly includes certain context data during serialization and deserialization, which allows attackers to execute arbitrary code via an application that sends a crafted Intent, aka internal bug 21437603.

    Published:1 Oct 2015
    Low

    CVE-2015-3825

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-3837. Reason: This candidate is a reservation duplicate of CVE-2015-3837. Notes: All CVE users should reference CVE-2015-3837 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published:18 Feb 2016
    7.5
    High

    CVE-2015-3798

    Last Modified: 22 Sept 2015

    The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression, a different vulnerability than CVE-2015-3796 and CVE-2015-3797.

    Source:Google Security Research
    Published:16 Aug 2015
    7.5
    High

    CVE-2015-3796

    Last Modified: 22 Sept 2015

    The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression, a different vulnerability than CVE-2015-3797 and CVE-2015-3798.

    Source:Google Security Research
    Published:16 Aug 2015
    7.5
    High

    CVE-2015-3783

    Last Modified: 22 Sept 2015

    SceneKit in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

    Source:Google Security Research
    Published:16 Aug 2015
    9.3
    Critical

    CVE-2015-3704

    Last Modified: 10 Sept 2015

    runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Source:Google Security Research
    Published:3 Jul 2015
    9.3
    Critical

    CVE-2015-3693

    Last Modified: 9 Mar 2015

    Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates for DDR3 RAM, which might make it easier for remote attackers to conduct row-hammer attacks, and consequently gain privileges or cause a denial of service (memory corruption), by triggering certain patterns of access to memory locations.

    Source:Google Security Research
    Published:3 Jul 2015
    7.2
    High

    CVE-2015-3673

    Last Modified: 31 Aug 2015

    Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root privileges by moving and then modifying Directory Utility.

    Source:Metasploit
    Published:3 Jul 2015
    7.8
    High

    CVE-2015-3643

    Last Modified: 23 Apr 2015

    usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call check_polkit for the KVMTest method.

    Source:Tavis Ormandy
    Published:27 Sept 2017
    4.9
    Medium

    CVE-2015-3636

    Last Modified: 12 Apr 2025

    The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) by leveraging the ability to make a SOCK_DGRAM socket system call for the IPPROTO_ICMP or IPPROTO_ICMPV6 protocol, and then making a connect system call after a disconnect.

    Published:2 May 2015
    4.3
    Medium

    CVE-2015-3632

    Last Modified: 29 Apr 2015

    Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.

    Source:Francis Provencher
    Published:1 May 2015
    9
    Critical

    CVE-2015-3628

    Last Modified: 29 Oct 2016

    The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP AAM 11.4.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0, BIG-IP GTM 11.3.0 before 11.6.0 HF6, BIG-IP PSM 11.3.0 through 11.4.1, Enterprise Manager 3.1.0 through 3.1.1, BIG-IQ Cloud and Security 4.0.0 through 4.5.0, BIG-IQ Device 4.2.0 through 4.5.0, and BIG-IQ ADC 4.5.0 allows remote authenticated users with the "Resource Administrator" role to gain privileges via an iCall (1) script or (2) handler in a SOAP request to iControl/iControlPortal.cgi.

    Source:Metasploit
    Published:7 Dec 2015
    5.8
    Medium

    CVE-2015-3624

    Last Modified: 16 Jun 2015

    Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.120) allows remote attackers to hijack the authentication of content administrators for requests that delete content via a delete action.

    Source:Jerold Hoong
    Published:9 Jun 2015
    6.4
    Medium

    CVE-2015-3623

    Last Modified: 2 Nov 2017

    XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgery (SSRF) attacks and read arbitrary files via crafted XML data in a request to AccessPoint.aspx.

    Source:Alex Haynes
    Published:16 Sept 2015
    7.7
    High

    CVE-2015-3456

    Last Modified: 21 May 2015

    The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.

    Source:Marcus Meissner
    Published:13 May 2015
    3.5
    Low

    CVE-2015-3443

    Last Modified: 26 Jun 2015

    Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before 8.8.000005 allows remote authenticated users to inject arbitrary web script or HTML via a password entry, which is not properly handled when toggling the password mask.

    Source:Marco Delai
    Published:2 Jul 2015
    4.3
    Medium

    CVE-2015-3440

    Last Modified: 4 May 2017

    Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type.

    Source:klikki
    Published:3 Aug 2015
    4.3
    Medium

    CVE-2015-3337

    Last Modified: 21 May 2015

    Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

    Source:pandujar
    Published:24 Apr 2015
    7.5
    High

    CVE-2015-3325

    Last Modified: 18 Aug 2015

    SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the show parameter in the QUERY_STRING to the default URI.

    Source:Hannes Trunde
    Published:15 May 2015
    7.8
    High

    CVE-2015-3315

    Last Modified: 27 Oct 2016

    Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/abrt/*/maps, (2) /tmp/jvm-*/hs_error.log, (3) /proc/*/exe, (4) /etc/os-release in a chroot, or (5) an unspecified root directory related to librpm.

    Source:Tavis Ormandy
    Published:14 Apr 2015
    8.1
    High

    CVE-2015-3314

    Last Modified: 21 Apr 2015

    SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.

    Source:Hannes Trunde
    Published:7 Sept 2017
    9.8
    Critical

    CVE-2015-3313

    Last Modified: 21 Apr 2015

    SQL injection vulnerability in WordPress Community Events plugin before 1.4.

    Source:Hannes Trunde
    Published:7 Sept 2017
    10
    Critical

    CVE-2015-3306

    Last Modified: 29 Aug 2017

    The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

    Source:Metasploit
    Published:18 May 2015
    7.5
    High

    CVE-2015-3302

    Last Modified: 29 Apr 2015

    The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism."

    Source:High-Tech Bridge SA
    Published:29 Dec 2017
    4
    Medium

    CVE-2015-3301

    Last Modified: 29 Apr 2015

    Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php.

    Source:High-Tech Bridge SA
    Published:14 May 2015
    4.3
    Medium

    CVE-2015-3300

    Last Modified: 29 Apr 2015

    Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote attackers to inject arbitrary web script or HTML via the (1) billing_firstname, (2) billing_lastname, (3) billing_company, (4) billing_tax_id_number, (5) billing_city, (6) billing_street, (7) billing_street_2, (8) billing_postcode, (9) billing_telephone_1, (10) billing_telephone_2, (11) billing_fax, (12) shipping_firstname, (13) shipping_lastname, (14) shipping_company, (15) shipping_tax_id_number, (16) shipping_city, (17) shipping_street, (18) shipping_street_2, (19) shipping_postcode, (20) shipping_telephone_1, (21) shipping_telephone_2, or (22) shipping_fax parameter to shopping-cart/checkout/; the (23) search_by parameter in the admin/AddressesList.php page to wp-admin/admin.php; the (24) address_id, (25) address_name, (26) firstname, (27) lastname, (28) street, (29) city, (30) postcode, or (31) email parameter in the admin/AddressEdit.php page to wp-admin/admin.php; the (32) post_id or (33) rel_type parameter in the admin/AssignedCategoriesList.php page to wp-admin/admin.php; or the (34) post_type parameter in the admin/CustomFieldsList.php page to wp-admin/admin.php.

    Source:High-Tech Bridge SA
    Published:14 May 2015
    10
    Critical

    CVE-2015-3292

    Last Modified: 17 Jun 2014

    The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:Metasploit
    Published:31 May 2015
    7.2
    High

    CVE-2015-3290

    Last Modified: 5 Aug 2015

    arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during nested NMI processing, which allows local users to gain privileges by triggering an NMI within a certain instruction window.

    Source:Andrew Lutomirski
    Published:22 Jul 2015
    5.3
    Medium

    CVE-2015-3271

    Last Modified: 12 Apr 2025

    Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.

    Published:15 Dec 2016
    4.6
    Medium

    CVE-2015-3256

    Last Modified: 12 Apr 2025

    PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (memory corruption and polkitd daemon crash) and possibly gain privileges via unspecified vectors, related to "javascript rule evaluation."

    Published:2 Jul 2015
    5.1
    Medium

    CVE-2015-3246

    Last Modified: 16 May 2018

    libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

    Source:Qualys Corporation
    Published:23 Jul 2015
    2.1
    Low

    CVE-2015-3245

    Last Modified: 16 May 2018

    Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a denial of service (/etc/passwd corruption) via a newline character in the GECOS field.

    Source:Qualys Corporation
    Published:23 Jul 2015
    3.3
    Low

    CVE-2015-3239

    Last Modified: 12 Apr 2025

    Off-by-one error in the dwarf_to_unw_regnum function in include/dwarf_i.h in libunwind 1.1 allows local users to have unspecified impact via invalid dwarf opcodes.

    Published:20 Jun 2015
    4.3
    Medium

    CVE-2015-3224

    Last Modified: 23 Mar 2017

    request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.

    Source:Metasploit
    Published:26 Jul 2015
    7
    High

    CVE-2015-3222

    Last Modified: 11 Jun 2015

    syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.

    Source:Andrew Widdersheim
    Published:7 Sept 2017
    4
    Medium

    CVE-2015-3221

    Last Modified: 24 Jun 2015

    OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.

    Source:hyp3rlinx
    Published:23 Jun 2015
    6.9
    Medium

    CVE-2015-3214

    Last Modified: 27 Aug 2015

    The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.

    Source:Google Security Research
    Published:16 Jun 2015
    7.5
    High

    CVE-2015-3205

    Last Modified: 10 Jun 2015

    libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file, related to "free" function calls in the "lexer's memory clean-up procedure."

    Source:Jeremy Brown
    Published:16 Jun 2015
    7.5
    High

    CVE-2015-3203

    Last Modified: 22 Sept 2015

    Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the href parameter.

    Source:rTheory
    Published:28 Sept 2015
    3.6
    Low

    CVE-2015-3202

    Last Modified: 10 Oct 2016

    fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.

    Source:Tavis Ormandy
    Published:21 May 2015