10
    Critical

    CVE-2015-0235

    Last Modified: 27 Oct 2016

    Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

    Source:1n3
    Published:27 Jan 2015
    7.5
    High

    CVE-2015-0231

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.

    Published:1 Jan 2015
    5
    Medium

    CVE-2015-0205

    Last Modified: 12 Apr 2025

    The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recognizes a Certification Authority with DH support.

    Published:8 Jan 2015
    5.3
    Medium

    CVE-2015-0204

    Last Modified: 12 Apr 2025

    The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and facilitate brute-force decryption by offering a weak ephemeral RSA key in a noncompliant role, related to the "FREAK" issue. NOTE: the scope of this CVE is only client code based on OpenSSL, not EXPORT_RSA issues associated with servers or other TLS implementations.

    Published:6 Jan 2015
    7.2
    High

    CVE-2015-0179

    Last Modified: 4 Sept 2017

    Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users to obtain the System privilege via unspecified vectors, aka SPR TCHL9SST8V.

    Source:ParagonSec
    Published:6 Apr 2015
    6.5
    Medium

    CVE-2015-0107

    Last Modified: 9 Feb 2015

    IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attacks via unspecified vectors.

    Source:Jakub Palaczynski
    Published:24 Apr 2017
    8.8
    High

    CVE-2015-0104

    Last Modified: 9 Feb 2015

    IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to execute arbitrary code via unspecified vectors.

    Source:Jakub Palaczynski
    Published:24 Apr 2017
    9.3
    Critical

    CVE-2015-0097

    Last Modified: 20 Jul 2015

    Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Word Local Zone Remote Code Execution Vulnerability."

    Source:Eduardo Braun Prado
    Published:11 Mar 2015
    9.3
    Critical

    CVE-2015-0096

    Last Modified: 18 Jul 2010

    Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, leading to DLL loading during Windows Explorer access to the icon of a crafted shortcut, aka "DLL Planting Remote Code Execution Vulnerability."

    Source:Ivanlef0u
    Published:11 Mar 2015
    9.3
    Critical

    CVE-2015-0081

    Last Modified: 7 Apr 2015

    Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS Remote Code Execution Vulnerability."

    Source:Francis Provencher
    Published:11 Mar 2015
    4.3
    Medium

    CVE-2015-0072

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFRAME element that does not trigger a redirect, and an eval of a WindowProxy object, aka "Universal XSS (UXSS)."

    Published:7 Feb 2015
    9.3
    Critical

    CVE-2015-0065

    Last Modified: 25 Aug 2015

    Microsoft Word 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "OneTableDocumentStream Remote Code Execution Vulnerability."

    Source:Google Security Research
    Published:11 Feb 2015
    9.3
    Critical

    CVE-2015-0064

    Last Modified: 25 Aug 2015

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applications 2010 SP2, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Office Remote Code Execution Vulnerability."

    Source:Google Security Research
    Published:11 Feb 2015
    4.7
    Medium

    CVE-2015-0060

    Last Modified: 1 Jun 2015

    The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly scale fonts, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Windows Font Driver Denial of Service Vulnerability."

    Source:Sky lake
    Published:11 Feb 2015
    6.9
    Medium

    CVE-2015-0059

    Last Modified: 1 Jun 2015

    win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted TrueType font, aka "TrueType Font Parsing Remote Code Execution Vulnerability."

    Source:Sky lake
    Published:11 Feb 2015
    7.2
    High

    CVE-2015-0058

    Last Modified: 1 Jun 2015

    Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a crafted application, aka "Windows Cursor Object Double Free Vulnerability."

    Source:Sky lake
    Published:11 Feb 2015
    7.2
    High

    CVE-2015-0057

    Last Modified: 1 Jun 2015

    win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

    Source:Sky lake
    Published:11 Feb 2015
    9.3
    Critical

    CVE-2015-0050

    Last Modified: 1 Dec 2016

    Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-8967 and CVE-2015-0044.

    Source:Skylined
    Published:11 Feb 2015
    9.3
    Critical

    CVE-2015-0040

    Last Modified: 1 Dec 2016

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0018, CVE-2015-0037, and CVE-2015-0066.

    Source:Skylined
    Published:11 Feb 2015
    7.8
    High

    CVE-2015-0016

    Last Modified: 3 Feb 2015

    Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Directory Traversal Elevation of Privilege Vulnerability."

    Source:Metasploit
    Published:13 Jan 2015
    1.9
    Low

    CVE-2015-0010

    Last Modified: 1 Jun 2015

    The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1, when the CRYPTPROTECTMEMORY_SAME_LOGON option is used, does not check an impersonation token's level, which allows local users to bypass intended decryption restrictions by leveraging a service that (1) has a named-pipe planting vulnerability or (2) uses world-readable shared memory for encrypted data, aka "CNG Security Feature Bypass Vulnerability" or MSRC ID 20707.

    Source:Sky lake
    Published:11 Feb 2015
    3.3
    Low

    CVE-2015-0009

    Last Modified: 11 Dec 2020

    The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows man-in-the-middle attackers to disable a signing requirement and trigger a revert-to-default action by spoofing domain-controller responses, aka "Group Policy Security Feature Bypass Vulnerability."

    Source:Thomas Zuk
    Published:11 Feb 2015
    8.3
    High

    CVE-2015-0008

    Last Modified: 11 Dec 2020

    The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authentication from the server to the client, which allows remote attackers to execute arbitrary code by making crafted data available on a UNC share, as demonstrated by Group Policy data from a spoofed domain controller, aka "Group Policy Remote Code Execution Vulnerability."

    Source:Thomas Zuk
    Published:11 Feb 2015
    6.1
    Medium

    CVE-2015-0006

    Last Modified: 12 Apr 2025

    The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to trigger an unintended permissive configuration by spoofing DNS and LDAP responses on a local network, aka "NLA Security Feature Bypass Vulnerability."

    Published:13 Jan 2015
    7.2
    High

    CVE-2015-0004

    Last Modified: 23 Jan 2015

    The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges by conducting a junction attack to load another user's UsrClass.dat registry hive, aka MSRC ID 20674 or "Microsoft User Profile Service Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:13 Jan 2015
    6.9
    Medium

    CVE-2015-0003

    Last Modified: 1 Jun 2015

    win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

    Source:Sky lake
    Published:11 Feb 2015
    7.2
    High

    CVE-2015-0002

    Last Modified: 14 Jul 2017

    The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify that an impersonation token is associated with an administrative account, which allows local users to gain privileges by running AppCompatCache.exe with a crafted DLL file, aka MSRC ID 20544 or "Microsoft Application Compatibility Infrastructure Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:13 Jan 2015
    Unknown

    CVE-2014-1106691

    https://github.com/dejkfirt0n66/kneedTanstack

    2.1
    Low

    CVE-2014-100039

    Last Modified: 20 Jan 2015

    mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a crafted size in an unspecified IOCTL call, which triggers an out-of-bounds read. NOTE: some of these details are obtained from third party information.

    Source:Parvez Anwar
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-100031

    Last Modified: 27 Feb 2014

    Multiple SQL injection vulnerabilities in Ganesha Digital Library (GDL) 4.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) download.php or (2) main.php.

    Source:ByEge
    Published:13 Jan 2015
    4.3
    Medium

    CVE-2014-100030

    Last Modified: 27 Feb 2014

    Cross-site scripting (XSS) vulnerability in module/search/function.php in Ganesha Digital Library (GDL) 4.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a ByEge action.

    Source:ByEge
    Published:13 Jan 2015
    5
    Medium

    CVE-2014-100029

    Last Modified: 27 Feb 2014

    Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) newlang or (2) newtheme parameter.

    Source:ByEge
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-100020

    Last Modified: 23 Jan 2014

    SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. NOTE: the CatID parameter is already covered by CVE-2008-0685.

    Source:vinicius777
    Published:13 Jan 2015
    4.3
    Medium

    CVE-2014-100017

    Last Modified: 8 Sept 2014

    Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitrary web script or HTML via the message field.

    Source:N0 Feel
    Published:13 Jan 2015
    6.4
    Medium

    CVE-2014-100015

    Last Modified: 10 Mar 2014

    Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write to arbitrary files via a .. (dot dot) in the filename in a file upload.

    Source:Metasploit
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-100014

    Last Modified: 19 Feb 2014

    Multiple stack-based buffer overflows in pdmwService.exe in SolidWorks Workgroup PDM 2014 SP2 allow remote attackers to execute arbitrary code via a long string in a (1) 2001, (2) 2002, or (3) 2003 opcode to port 3000.

    Source:Mohamed Shetta
    Published:13 Jan 2015
    4.3
    Medium

    CVE-2014-100013

    Last Modified: 17 Nov 2014

    Multiple cross-site scripting (XSS) vulnerabilities in clientResponse 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Subject or (2) Message field.

    Source:Halil Dalabasmaz
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-100012

    Last Modified: 25 Feb 2014

    SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote attackers to execute arbitrary SQL commands via the i parameter.

    Source:Hurley
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-100011

    Last Modified: 11 Apr 2014

    SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Source:delme
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-100003

    Last Modified: 14 Oct 2014

    SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ym_download_id parameter to the default URI.

    Source:TranDinhTien
    Published:13 Jan 2015
    5
    Medium

    CVE-2014-100002

    Last Modified: 29 Jan 2014

    Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket.

    Source:xistence
    Published:13 Jan 2015
    Unknown

    CVE-2014-91371

    https://github.com/jamaal001/CVE-2014-91371-Wordpress-

    Low

    CVE-2014-62771

    Last Modified: 25 Sept 2014

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6271. Reason: This candidate is a duplicate of CVE-2014-6271. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2014-6271 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Shaun Colley
    Published:13 Jan 2015
    5.3
    Medium

    CVE-2014-10079

    Last Modified: 15 Mar 2019

    In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash.

    Source:Gionathan Reale
    Published:23 Feb 2019
    6.1
    Medium

    CVE-2014-10078

    Last Modified: 15 Mar 2019

    Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php, interface/registerclient/onlineregfailure.php, and interface/registercustomer/onlineregfailure.php.

    Source:Gionathan Reale
    Published:23 Feb 2019
    7.5
    High

    CVE-2014-10069

    Last Modified: 21 Nov 2024

    Hitron CVE-30360 devices use a 578A958E3DD933FC DES key that is shared across different customers' installations, which makes it easier for attackers to obtain sensitive information by decrypting a backup configuration file, as demonstrated by a password hash in the um_auth_account_password field.

    Published:7 Jan 2018
    7.5
    High

    CVE-2014-10038

    Last Modified: 15 Jan 2014

    SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitrary SQL commands via the ids parameter.

    Source:Houssamix
    Published:13 Jan 2015
    7.5
    High

    CVE-2014-10037

    Last Modified: 17 Jan 2014

    Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a .. (dot dot) in the url parameter to photoalbum/index.php.

    Source:Houssamix
    Published:13 Jan 2015
    4.3
    Medium

    CVE-2014-10035

    Last Modified: 3 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to inject arbitrary web script or HTML via the (1) sEcho parameter to comments_paginate.php or (2) stores_paginate.php or the (3) affiliate_url, (4) description, (5) domain, (6) seo[description], (7) seo[heading], (8) seo[title], (9) seo[keywords], (10) setting[logo], (11) setting[perpage], or (12) setting[sitename] to admin/index.php.

    Source:LiquidWorm
    Published:13 Jan 2015
    6.5
    Medium

    CVE-2014-10034

    Last Modified: 3 Mar 2014

    Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execute arbitrary SQL commands via the (1) iDisplayLength or (2) iDisplayStart parameter to (a) comments_paginate.php or (b) stores_paginate.php in admin/ajax/.

    Source:LiquidWorm
    Published:13 Jan 2015