4.3
    Medium

    CVE-2015-1366

    Last Modified: 20 Jan 2015

    Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the image_user parameter.

    Source:Hans-Martin Muench
    Published:27 Jan 2015
    5
    Medium

    CVE-2015-1365

    Last Modified: 20 Jan 2015

    Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbitrary files via a .. (dot dot) in the q parameter.

    Source:Hans-Martin Muench
    Published:27 Jan 2015
    7.5
    High

    CVE-2015-1364

    Last Modified: 26 Jan 2015

    SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter to register/.

    Source:TranDinhTien
    Published:27 Jan 2015
    7.5
    High

    CVE-2015-1362

    Last Modified: 22 Jan 2015

    Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary code via a long string in the maker element in an XML file.

    Source:Osanda Malith Jayathissa
    Published:27 Jan 2015
    7.2
    High

    CVE-2015-1338

    Last Modified: 29 Sept 2015

    kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.

    Source:halfdog
    Published:1 Oct 2015
    7.8
    High

    CVE-2015-1336

    Last Modified: 25 Jan 2017

    The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.

    Source:halfdog
    Published:13 Dec 2015
    7.8
    High

    CVE-2015-1328

    Last Modified: 2 Nov 2016

    The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local users to obtain root access by leveraging a configuration in which overlayfs is permitted in an arbitrary mount namespace.

    Source:Metasploit
    Published:28 Nov 2016
    7
    High

    CVE-2015-1325

    Last Modified: 29 May 2015

    Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write to arbitrary files and gain root privileges.

    Source:rebel
    Published:25 Aug 2017
    7.2
    High

    CVE-2015-1318

    Last Modified: 21 Apr 2015

    The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).

    Source:Ricardo F. Teixeira
    Published:17 Apr 2015
    6.9
    Medium

    CVE-2015-1305

    Last Modified: 30 Jan 2015

    McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call.

    Source:Parvez Anwar
    Published:6 Feb 2015
    7.5
    High

    CVE-2015-1265

    Last Modified: 15 Aug 2015

    Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Source:Paulos Yibelo
    Published:19 May 2015
    9.8
    Critical

    CVE-2015-1187

    Last Modified: 23 Mar 2017

    The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

    Source:Metasploit
    Published:21 Sept 2017
    7.5
    High

    CVE-2015-1172

    Last Modified: 23 Mar 2017

    Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 and earlier for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in an unspecified directory.

    Source:Metasploit
    Published:11 Feb 2015
    10
    Critical

    CVE-2015-1171

    Last Modified: 20 Jan 2015

    Stack-based buffer overflow in GSM SIM Utility (aka SIM Card Editor) 6.6 allows remote attackers to execute arbitrary code via a long entry in a .sms file.

    Source:Osanda Malith Jayathissa
    Published:28 Aug 2015
    10
    Critical

    CVE-2015-1158

    Last Modified: 12 Apr 2018

    The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code.

    Source:@0x00string
    Published:10 Jun 2015
    7.8
    High

    CVE-2015-1157

    Last Modified: 12 Apr 2025

    CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2) a WhatsApp message.

    Published:28 May 2015
    7.2
    High

    CVE-2015-1140

    Last Modified: 12 Apr 2025

    Buffer overflow in IOHIDFamily in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors.

    Published:10 Apr 2015
    7.8
    High

    CVE-2015-1130

    Last Modified: 13 Apr 2015

    The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

    Source:Metasploit
    Published:10 Apr 2015
    5.4
    Medium

    CVE-2015-1100

    Last Modified: 21 Apr 2015

    The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service (out-of-bounds memory access) or obtain sensitive memory-content information via a crafted app.

    Source:Maxime Villard
    Published:10 Apr 2015
    5.8
    Medium

    CVE-2015-1060

    Last Modified: 6 Jan 2015

    Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.

    Source:LiquidWorm
    Published:16 Jan 2015
    6.5
    Medium

    CVE-2015-1059

    Last Modified: 6 Jan 2015

    Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in /app/webroot/uploads.

    Source:LiquidWorm
    Published:16 Jan 2015
    4.3
    Medium

    CVE-2015-1058

    Last Modified: 6 Jan 2015

    Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Category][title] parameter to admin/categories/add, (2) data[Field][title] parameter to admin/fields/ajax_fields/, (3) name property in a basicInfo JSON object to admin/tools/create_theme, (4) data[Link][link_title] parameter to admin/links/links/add, or (5) data[ForumTopic][subject] parameter to forums/off-topic/new.

    Source:LiquidWorm
    Published:16 Jan 2015
    4.3
    Medium

    CVE-2015-1057

    Last Modified: 3 Jan 2015

    Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary web script or HTML via the "Real Name" value.

    Source:Ahmet Agar / 0x97
    Published:16 Jan 2015
    3.5
    Low

    CVE-2015-1054

    Last Modified: 4 Jan 2015

    Cross-site scripting (XSS) vulnerability in the Games feature in Crea8Social 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the Game Content field in Add Game.

    Source:Yudhistira B W
    Published:16 Jan 2015
    3.5
    Low

    CVE-2015-1028

    Last Modified: 18 Jan 2015

    Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remote authenticated users to inject arbitrary web script or HTML via the (1) domainname parameter to dnsProxy.cmd (DNS Proxy Configuration Panel); the (2) brName parameter to lancfg2get.cgi (Lan Configuration Panel); the (3) wlAuthMode, (4) wl_wsc_reg, or (5) wl_wsc_mode parameter to wlsecrefresh.wl (Wireless Security Panel); or the (6) wlWpaPsk parameter to wlsecurity.wl (Wireless Password Viewer).

    Source:XLabs Security
    Published:21 Jan 2015
    9.8
    Critical

    CVE-2015-0936

    Last Modified: 23 Mar 2017

    Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.

    Source:Metasploit
    Published:1 Jun 2017
    7.5
    High

    CVE-2015-0935

    Last Modified: 15 Jun 2016

    Bomgar Remote Support before 15.1.1 allows remote attackers to execute arbitrary PHP code via crafted serialized data to unspecified PHP scripts.

    Source:Markus Wulftange
    Published:25 May 2015
    9
    Critical

    CVE-2015-0925

    Last Modified: 16 Mar 2015

    The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperly handled by a subprocess reached through a named pipe, as demonstrated by a UNC share pathname.

    Source:Metasploit
    Published:22 Jan 2015
    7.5
    High

    CVE-2015-0919

    Last Modified: 7 Jan 2015

    Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrators to execute arbitrary SQL commands via the (1) idcat or (2) idclient parameter to backend/main.php.

    Source:Steffen Rösemann
    Published:8 Jan 2015
    5
    Medium

    CVE-2015-0816

    Last Modified: 27 Oct 2016

    Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.

    Source:Metasploit
    Published:31 Mar 2015
    5
    Medium

    CVE-2015-0802

    Last Modified: 27 Oct 2016

    Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of access to restricted internal methods.

    Source:Metasploit
    Published:31 Mar 2015
    10
    Critical

    CVE-2015-0779

    Last Modified: 8 May 2015

    Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a crafted directory name in the uid parameter, in conjunction with a WAR filename in the filename parameter and WAR content in the POST data, a different vulnerability than CVE-2010-5323 and CVE-2010-5324.

    Source:Metasploit
    Published:7 Jun 2015
    7.8
    High

    CVE-2015-0569

    Last Modified: 25 Jan 2016

    Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via a crafted application that establishes a packet filter.

    Source:Shawn the R0ck
    Published:9 May 2016
    7.8
    High

    CVE-2015-0568

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the msm_set_crop function in drivers/media/video/msm/msm_camera.c in the MSM-Camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (memory corruption) via an application that makes a crafted ioctl call.

    Published:7 Aug 2015
    10
    Critical

    CVE-2015-0565

    Last Modified: 4 Sept 2016

    NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.

    Source:Google Security Research
    Published:25 Feb 2020
    6.8
    Medium

    CVE-2015-0555

    Last Modified: 23 Feb 2015

    Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrary code via a long string in the first argument to the (1) ReadConfigValue or (2) WriteConfigValue function.

    Source:Praveen Darshanam
    Published:24 Feb 2015
    9.4
    Critical

    CVE-2015-0554

    Last Modified: 7 Jan 2015

    The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly restrict access to the web interface, which allows remote attackers to obtain sensitive information or cause a denial of service (device restart) as demonstrated by a direct request to (1) wlsecurity.html or (2) resetrouter.html.

    Source:Eduardo Novella
    Published:21 Jan 2015
    4
    Medium

    CVE-2015-0516

    Last Modified: 19 Mar 2015

    Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL.

    Source:Han Sahin
    Published:21 Jan 2015
    5
    Medium

    CVE-2015-0514

    Last Modified: 19 Mar 2015

    EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access to conduct a decryption attack.

    Source:Han Sahin
    Published:21 Jan 2015
    1.5
    Low

    CVE-2015-0493

    Last Modified: 27 Oct 2016

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-0474.

    Source:Francis Provencher
    Published:16 Apr 2015
    1.5
    Low

    CVE-2015-0474

    Last Modified: 27 Oct 2016

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-0493.

    Source:Francis Provencher
    Published:16 Apr 2015
    10
    Critical

    CVE-2015-0359

    Last Modified: 8 May 2015

    Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0346.

    Source:Metasploit
    Published:14 Apr 2015
    4.3
    Medium

    CVE-2015-0345

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 16 and 11 before Update 5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published:15 Apr 2015
    9.3
    Critical

    CVE-2015-0336

    Last Modified: 8 May 2015

    Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-0334.

    Source:Metasploit
    Published:12 Mar 2015
    10
    Critical

    CVE-2015-0318

    Last Modified: 17 Mar 2015

    Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0321, CVE-2015-0329, and CVE-2015-0330.

    Source:Metasploit
    Published:4 Feb 2015
    7.8
    High

    CVE-2015-0313

    Last Modified: 25 Mar 2015

    Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.

    Source:SecurityObscurity
    Published:2 Feb 2015
    7.8
    High

    CVE-2015-0311

    Last Modified: 12 Mar 2015

    Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.

    Source:Metasploit
    Published:23 Jan 2015
    7.5
    High

    CVE-2015-0273

    Last Modified: 23 Feb 2015

    Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allow remote attackers to execute arbitrary code via crafted serialized input containing a (1) R or (2) r type specifier in (a) DateTimeZone data handled by the php_date_timezone_initialize_from_hash function or (b) DateTime data handled by the php_date_initialize_from_hash function.

    Source:Taoguang Chen
    Published:19 Feb 2015
    5
    Medium

    CVE-2015-0252

    Last Modified: 4 May 2015

    internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.

    Source:beford
    Published:20 Mar 2015
    10
    Critical

    CVE-2015-0240

    Last Modified: 27 Mar 2017

    The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

    Source:sleepya
    Published:23 Feb 2015