Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-4917 | 1 Oracle | 1 Supply Chain Products Suite | 2016-12-23 | 3.5 LOW | N/A |
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2015-4892. | |||||
CVE-2015-4938 | 1 Ibm | 1 Websphere Application Server | 2016-12-23 | 5.0 MEDIUM | N/A |
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information via unspecified vectors. | |||||
CVE-2015-5161 | 1 Zend | 1 Zend Framework | 2016-12-23 | 6.8 MEDIUM | N/A |
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters. | |||||
CVE-2015-5435 | 1 Hp | 2 Integrated Lights-out 3 Firmware, Integrated Lights-out 4 Firmware | 2016-12-23 | 4.0 MEDIUM | N/A |
Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 3 before 1.85 and 4 before 2.22 allows remote authenticated users to cause a denial of service via unknown vectors. | |||||
CVE-2015-5448 | 1 Numara | 1 Asset Manager | 2016-12-23 | 2.1 LOW | N/A |
HP Asset Manager 9.40 and 9.41 before 9.41.11103 P4-rev1 and 9.50 before 9.50.11925 P3 allows local users to obtain sensitive information via unspecified vectors. | |||||
CVE-2015-5536 | 1 Belkin | 2 N300 Dual-band Wi-fi Range Extender, N300 Dual-band Wi-fi Range Extender Firmware | 2016-12-23 | 9.0 HIGH | N/A |
Belkin N300 Dual-Band Wi-Fi Range Extender with firmware before 1.04.10 allows remote authenticated users to execute arbitrary commands via the (1) sub_dir parameter in a formUSBStorage request; pinCode parameter in a (2) formWpsStart or (3) formiNICWpsStart request; (4) wps_enrolee_pin parameter in a formWlanSetupWPS request; or unspecified parameters in a (5) formWlanMP, (6) formBSSetSitesurvey, (7) formHwSet, or (8) formConnectionSetting request. | |||||
CVE-2015-5611 | 1 Fca | 1 Uconnect | 2016-12-23 | 8.3 HIGH | N/A |
Unspecified vulnerability in Uconnect before 15.26.1, as used in certain Fiat Chrysler Automobiles (FCA) from 2013 to 2015 models, allows remote attackers in the same cellular network to control vehicle movement, cause human harm or physical damage, or modify dashboard settings via vectors related to modification of entertainment-system firmware and access of the CAN bus due to insufficient "Radio security protection," as demonstrated on a 2014 Jeep Cherokee Limited FWD. | |||||
CVE-2015-5746 | 1 Apple | 1 Iphone Os | 2016-12-23 | 5.0 MEDIUM | N/A |
AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling. | |||||
CVE-2015-5749 | 1 Apple | 1 Iphone Os | 2016-12-23 | 4.3 MEDIUM | N/A |
The Sandbox_profiles component in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox protection mechanism and read arbitrary managed preferences via a crafted app. | |||||
CVE-2015-5752 | 1 Apple | 1 Iphone Os | 2016-12-23 | 5.0 MEDIUM | N/A |
Backup in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via a crafted app that creates a symlink. | |||||
CVE-2015-5755 | 1 Apple | 3 Iphone Os, Itunes, Mac Os X | 2016-12-23 | 6.8 MEDIUM | N/A |
CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5761. | |||||
CVE-2015-5756 | 1 Apple | 2 Iphone Os, Mac Os X | 2016-12-23 | 6.8 MEDIUM | N/A |
FontParser in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-3804 and CVE-2015-5775. | |||||
CVE-2015-5757 | 1 Apple | 2 Iphone Os, Mac Os X | 2016-12-23 | 9.3 HIGH | N/A |
libpthread in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via an app that uses a crafted syscall to interfere with locking. | |||||
CVE-2015-5758 | 1 Apple | 2 Iphone Os, Mac Os X | 2016-12-23 | 6.8 MEDIUM | N/A |
ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image. | |||||
CVE-2015-5759 | 1 Apple | 1 Iphone Os | 2016-12-23 | 5.0 MEDIUM | N/A |
WebKit in Apple iOS before 8.4.1 allows remote attackers to spoof clicks via a crafted web site that leverages tap events. | |||||
CVE-2015-5761 | 1 Apple | 3 Iphone Os, Itunes, Mac Os X | 2016-12-23 | 6.8 MEDIUM | N/A |
CoreText in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted font file, a different vulnerability than CVE-2015-5755. | |||||
CVE-2015-5766 | 1 Apple | 1 Iphone Os | 2016-12-23 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in Air Traffic in Apple iOS before 8.4.1 allows attackers to access arbitrary filesystem locations via vectors related to asset handling. | |||||
CVE-2015-5769 | 1 Apple | 1 Iphone Os | 2016-12-23 | 7.1 HIGH | N/A |
The MSVDX driver in Apple iOS before 8.4.1 allows remote attackers to cause a denial of service (device crash) via a crafted video. | |||||
CVE-2015-5770 | 1 Apple | 1 Iphone Os | 2016-12-23 | 5.8 MEDIUM | N/A |
MobileInstallation in Apple iOS before 8.4.1 does not ensure the uniqueness of universal provisioning profile bundle IDs, which allows attackers to replace arbitrary extensions via a crafted enterprise app. | |||||
CVE-2015-5773 | 1 Apple | 2 Iphone Os, Mac Os X | 2016-12-23 | 6.8 MEDIUM | N/A |
QL Office in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted office document. |