9.3
    Critical

    CVE-2015-2464

    Last Modified: 21 Aug 2015

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allow remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2463.

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2463

    Last Modified: 21 Aug 2015

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allow remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2464.

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2462

    Last Modified: 21 Aug 2015

    ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2461

    Last Modified: 21 Aug 2015

    ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2458 and CVE-2015-2459.

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2460

    Last Modified: 21 Aug 2015

    ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2459

    Last Modified: 21 Aug 2015

    ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2458 and CVE-2015-2461.

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2458

    Last Modified: 21 Aug 2015

    ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2459 and CVE-2015-2461.

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2456

    Last Modified: 21 Aug 2015

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allow remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2455.

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2455

    Last Modified: 21 Aug 2015

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allow remote attackers to execute arbitrary code via a crafted TrueType font, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2456.

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2444

    Last Modified: 12 Aug 2015

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2442.

    Source:Blue Frost Security GmbH
    Published:14 Aug 2015
    2.1
    Low

    CVE-2015-2433

    Last Modified: 17 Sept 2015

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability."

    Source:Metasploit
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2432

    Last Modified: 21 Aug 2015

    ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability."

    Source:Google Security Research
    Published:15 Aug 2015
    9.3
    Critical

    CVE-2015-2431

    Last Modified: 21 Aug 2015

    Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Library (OGL) font, aka "Microsoft Office Graphics Component Remote Code Execution Vulnerability."

    Source:Google Security Research
    Published:15 Aug 2015
    8.8
    High

    CVE-2015-2426

    Last Modified: 17 Sept 2015

    Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Driver Vulnerability."

    Source:Metasploit
    Published:20 Jul 2015
    8.8
    High

    CVE-2015-2419

    Last Modified: 24 May 2018

    JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."

    Source:checkpoint
    Published:14 Jul 2015
    7.2
    High

    CVE-2015-2370

    Last Modified: 13 Aug 2015

    The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not prevent DCE/RPC connection reflection, which allows local users to gain privileges via a crafted application, aka "Windows RPC Elevation of Privilege Vulnerability."

    Source:monoxgas
    Published:14 Jul 2015
    7.2
    High

    CVE-2015-2366

    Last Modified: 22 Sept 2015

    win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

    Source:Nils Sommer
    Published:14 Jul 2015
    7.2
    High

    CVE-2015-2365

    Last Modified: 22 Sept 2015

    win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

    Source:Nils Sommer
    Published:14 Jul 2015
    10
    Critical

    CVE-2015-2342

    Last Modified: 17 Feb 2015

    The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.

    Source:Metasploit
    Published:12 Oct 2015
    4.3
    Medium

    CVE-2015-2321

    Last Modified: 7 Aug 2015

    Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the email field.

    Source:Owais Mehtab
    Published:13 Aug 2015
    4.3
    Medium

    CVE-2015-2315

    Last Modified: 16 Mar 2015

    Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup action to the default URI.

    Source:Jouko Pynnonen
    Published:17 Mar 2015
    7.5
    High

    CVE-2015-2314

    Last Modified: 16 Mar 2015

    SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax action to comments/feed.

    Source:Jouko Pynnonen
    Published:17 Mar 2015
    6.8
    Medium

    CVE-2015-2295

    Last Modified: 26 Mar 2015

    Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deletefile parameter.

    Source:High-Tech Bridge SA
    Published:10 Apr 2015
    6.5
    Medium

    CVE-2015-2292

    Last Modified: 10 Oct 2016

    Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) order_by or (2) order parameter in the wpseo_bulk-editor page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

    Source:Ryan Dewhurst
    Published:17 Mar 2015
    7.8
    High

    CVE-2015-2291

    Last Modified: 16 Mar 2015

    (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.

    Source:Glafkos Charalambous
    Published:9 Aug 2017
    7.2
    High

    CVE-2015-2285

    Last Modified: 30 Mar 2017

    The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu Vivid 15.04, allows local users to execute arbitrary commands and gain privileges via a crafted file in /run/user/*/upstart/sessions/.

    Source:halfdog
    Published:12 Mar 2015
    10
    Critical

    CVE-2015-2284

    Last Modified: 8 Apr 2015

    userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary code via unspecified vectors, related to client session handling.

    Source:Metasploit
    Published:24 Mar 2015
    7.5
    High

    CVE-2015-2281

    Last Modified: 18 Mar 2015

    Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message Dispatcher on TCP port 8000.

    Source:Core Security
    Published:19 Mar 2015
    8.8
    High

    CVE-2015-2280

    Last Modified: 8 Jul 2015

    snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the mac parameter.

    Source:Core Security
    Published:24 Jul 2017
    9.8
    Critical

    CVE-2015-2279

    Last Modified: 8 Jul 2015

    cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows remote attackers to execute arbitrary OS commands via shell metacharacters after an "&" (ampersand) in the write_mac write_pid, write_msn, write_tan, or write_hdv parameter.

    Source:Core Security
    Published:24 Jul 2017
    4.3
    Medium

    CVE-2015-2275

    Last Modified: 16 Mar 2015

    Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to inject arbitrary web script or HTML via the parameters[data][7][title] parameter in a saveImageData action to index.php/AJAXProxy.

    Source:ITAS Team
    Published:12 Mar 2015
    3.5
    Low

    CVE-2015-2269

    Last Modified: 17 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) alt or (2) title attribute in an IMG element.

    Source:LiquidWorm
    Published:1 Jun 2015
    6.8
    Medium

    CVE-2015-2248

    Last Modified: 7 May 2015

    Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for requests that create bookmarks via a crafted request to cgi-bin/editBookmark.

    Source:Veit Hailperin
    Published:1 May 2015
    7.5
    High

    CVE-2015-2237

    Last Modified: 12 Mar 2015

    Multiple SQL injection vulnerabilities in Betster (aka PHP Betoffice) 1.0.4 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) showprofile.php or (2) categoryedit.php or (3) username parameter in a login to index.php.

    Source:ZeQ3uL
    Published:12 Mar 2015
    Unknown

    CVE-2015-2231

    https://github.com/rednaga/adups-get-super-serial

    4.3
    Medium

    CVE-2015-2223

    Last Modified: 31 Mar 2015

    Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks Traps (formerly Cyvera Endpoint Protection) 3.1.2.1546 allow remote attackers to inject arbitrary web script or HTML via the (1) Arguments, (2) FileName, or (3) URL parameter in a SOAP request.

    Source:Michael Hendrickx
    Published:14 Apr 2015
    7.2
    High

    CVE-2015-2219

    Last Modified: 23 Mar 2017

    Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.

    Source:Metasploit
    Published:12 May 2015
    4.3
    Medium

    CVE-2015-2218

    Last Modified: 26 Sept 2016

    Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) item[name] or (2) item[customcss] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or the itemid parameter in the (3) wonderplugin_audio_show_item or (4) wonderplugin_audio_edit_item page to wp-admin/admin.php.

    Source:Kacper Szurek
    Published:5 Mar 2015
    7.5
    High

    CVE-2015-2216

    Last Modified: 3 May 2018

    SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to execute arbitrary SQL commands via the prod_id parameter.

    Source:ayastar
    Published:5 Mar 2015
    7.5
    High

    CVE-2015-2208

    Last Modified: 3 Mar 2015

    The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the object parameter.

    Source:@u0x
    Published:12 Mar 2015
    6.5
    Medium

    CVE-2015-2199

    Last Modified: 26 Sept 2016

    Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote authenticated users to execute arbitrary SQL commands via the item[id] parameter in a wonderplugin_audio_save_item action to wp-admin/admin-ajax.php or remote administrators to execute arbitrary SQL commands via the itemid parameter in the (2) wonderplugin_audio_show_item, (3) wonderplugin_audio_show_items, or (4) wonderplugin_audio_edit_item page to wp-admin/admin.php.

    Source:Kacper Szurek
    Published:3 Mar 2015
    4.3
    Medium

    CVE-2015-2198

    Last Modified: 24 Feb 2015

    Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) homepage_url, (2) pic_url, or (3) avatar_url parameter, which are not properly handled in an error message.

    Source:Halil Dalabasmaz
    Published:3 Mar 2015
    7.5
    High

    CVE-2015-2196

    Last Modified: 24 Feb 2015

    SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.

    Source:Mateusz Lach
    Published:3 Mar 2015
    5
    Medium

    CVE-2015-2184

    Last Modified: 28 Nov 2016

    ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function.

    Source:Steffen Rösemann
    Published:10 Mar 2015
    7.5
    High

    CVE-2015-2183

    Last Modified: 28 Nov 2016

    Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execute arbitrary SQL commands via the id parameter in a (1) disporders detail or (2) subadminmgt edit action or (3) cid parameter in an editcurrency action to admin/.

    Source:Steffen Rösemann
    Published:10 Mar 2015
    4.3
    Medium

    CVE-2015-2182

    Last Modified: 28 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script or HTML via the (1) schltr parameter in a brands action or (2) brand parameter in a viewbrands action to index.php. NOTE: The search parameter vector is already covered by CVE-2010-5322.

    Source:Steffen Rösemann
    Published:11 Mar 2015
    7.5
    High

    CVE-2015-2177

    Last Modified: 30 May 2018

    Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via crafted packets on (1) TCP port 102 or (2) Profibus.

    Source:t4rkd3vilz
    Published:7 Mar 2015
    4.3
    Medium

    CVE-2015-2169

    Last Modified: 26 Jun 2015

    Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attackers to inject arbitrary web script or HTML via a Publisher registry entry, which is not properly handled when the machine is scanned.

    Source:Suraj Krishnaswami
    Published:24 Jun 2015
    5
    Medium

    CVE-2015-2166

    Last Modified: 2 Apr 2015

    Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI.

    Source:Anastasios Monachos
    Published:6 Apr 2015
    7.5
    High

    CVE-2015-2156

    Last Modified: 20 Apr 2025

    Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.

    Published:9 May 2015