Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-6547 | 1 Symantec | 1 Web Gateway | 2016-12-21 | 8.3 HIGH | N/A |
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands at boot time via unspecified vectors. | |||||
CVE-2015-6548 | 1 Symantec | 1 Web Gateway | 2016-12-21 | 5.8 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in a PHP script in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-6580 | 1 Google | 2 Chrome, V8 | 2016-12-21 | 7.5 HIGH | N/A |
Multiple unspecified vulnerabilities in Google V8 before 4.5.103.29, as used in Google Chrome before 45.0.2454.85, allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | |||||
CVE-2015-6581 | 1 Google | 1 Chrome | 2016-12-21 | 7.5 HIGH | N/A |
Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure. | |||||
CVE-2015-6582 | 1 Google | 1 Chrome | 2016-12-21 | 6.8 MEDIUM | N/A |
The decompose function in platform/transforms/TransformationMatrix.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not verify that a matrix inversion succeeded, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted web site. | |||||
CVE-2015-6583 | 1 Google | 1 Chrome | 2016-12-21 | 4.3 MEDIUM | N/A |
Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app's window after navigation away from the installation site, which might make it easier for remote attackers to spoof content via a crafted app, related to browser.cc and hosted_app_browser_controller.cc. | |||||
CVE-2015-6655 | 1 Pligg | 1 Pligg Cms | 2016-12-21 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php. | |||||
CVE-2015-6672 | 1 Citrix | 2 Netscaler Application Delivery Controller Firmware, Netscaler Gateway Firmware | 2016-12-21 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2015-6675 | 1 Siemens | 1 Ruggedcom Rugged Operating System | 2016-12-21 | 4.3 MEDIUM | N/A |
Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation protection mechanism via IP traffic. | |||||
CVE-2015-6680 | 1 Adobe | 1 Shockwave Player | 2016-12-21 | 10.0 HIGH | N/A |
Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6681. | |||||
CVE-2015-6681 | 1 Adobe | 1 Shockwave Player | 2016-12-21 | 10.0 HIGH | N/A |
Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6680. | |||||
CVE-2015-6805 | 1 Medhabidotcom | 1 Mdc Private Message | 2016-12-21 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the message field in a private message. | |||||
CVE-2015-6819 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-21 | 7.5 HIGH | N/A |
Multiple integer underflows in the ff_mjpeg_decode_frame function in libavcodec/mjpegdec.c in FFmpeg before 2.7.2 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted MJPEG data. | |||||
CVE-2015-6827 | 1 Auto-exchanger | 1 Auto-exchanger | 2016-12-21 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests that change a password via a request to signup.php. | |||||
CVE-2015-6830 | 1 Phpmyadmin | 1 Phpmyadmin | 2016-12-21 | 5.0 MEDIUM | N/A |
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha. | |||||
CVE-2015-6908 | 2 Apple, Openldap | 2 Mac Os X, Openldap | 2016-12-21 | 5.0 MEDIUM | N/A |
The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER data, as demonstrated by an attack against slapd. | |||||
CVE-2015-6943 | 1 S9y | 1 Serendipity | 2016-12-21 | 6.0 MEDIUM | N/A |
SQL injection vulnerability in the serendipity_checkCommentToken function in include/functions_comments.inc.php in Serendipity before 2.0.2, when "Use Tokens for Comment Moderation" is enabled, allows remote administrators to execute arbitrary SQL commands via the serendipity[id] parameter to serendipity_admin.php. | |||||
CVE-2015-6948 | 1 Corel | 1 Wordperfect | 2016-12-21 | 6.8 MEDIUM | N/A |
Heap-based buffer overflow in the Microsoft Word document conversion feature in Corel WordPerfect allows remote attackers to execute arbitrary code via a crafted document. | |||||
CVE-2015-6949 | 1 Asus | 1 Tm-1900 | 2016-12-21 | 9.3 HIGH | N/A |
Stack-based buffer overflow in the ASUS TM-AC1900 router allows remote attackers to execute arbitrary code via crafted HTTP header values. | |||||
CVE-2015-6962 | 1 Teiko | 1 Farol | 2016-12-21 | 7.5 HIGH | N/A |
SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands via the email parameter to tkmonitor/estrutura/login/Login.actions.php. |