Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-8511 | 1 Mozilla | 1 Firefox Os | 2016-01-14 | 6.9 MEDIUM | 6.4 MEDIUM |
Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors. | |||||
CVE-2015-8225 | 1 Huawei | 2 Ale Firmware, Gem-703l Firmware | 2016-01-14 | 7.1 HIGH | 5.5 MEDIUM |
The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL00C00B220 and ALE-TL00C01B220 and GEM-703L smartphones with software before V100R001C233B111 allows remote attackers to cause a denial of service (crash) via a crafted application with the system or camera permission, a different vulnerability than CVE-2015-8226. | |||||
CVE-2015-8597 | 1 Bluecoat | 2 Advanced Secure Gateway, Proxysg | 2016-01-13 | 5.8 MEDIUM | 7.4 HIGH |
Open redirect vulnerability in Blue Coat ProxySG 6.5 before 6.5.8.8 and 6.6 and Advanced Secure Gateway (ASG) 6.6 might allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a base64-encoded URL in conjunction with a "clear text" one in a coaching page, as demonstrated by "http://www.%humbug-URL%.local/bluecoat-splash-API?%BASE64-URL%." | |||||
CVE-2015-8303 | 1 Huawei | 1 Document Security Management | 2016-01-13 | 2.1 LOW | 4.0 MEDIUM |
Huawei Document Security Management (DSM) with software before V100R002C05SPC661 does not clear the clipboard when closing a secure file, which allows local users to obtain sensitive information by pasting the contents to another file. | |||||
CVE-2015-8226 | 1 Huawei | 2 Ale Firmware, Gem-703l Firmware | 2016-01-13 | 7.1 HIGH | 5.5 MEDIUM |
The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL00C00B220 and ALE-TL00C01B220 and GEM-703L smartphones with software before V100R001C233B111 allows remote attackers to cause a denial of service (crash) via a crafted application with the system or camera permission, a different vulnerability than CVE-2015-8225. | |||||
CVE-2015-7754 | 1 Juniper | 1 Screenos | 2016-01-13 | 9.3 HIGH | 8.1 HIGH |
Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or execute arbitrary code via crafted SSH negotiation. | |||||
CVE-2015-6566 | 2 Fedoraproject, Zarafa | 2 Fedora, Zarafa Collaboration Platform | 2016-01-13 | 7.2 HIGH | 8.4 HIGH |
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*. | |||||
CVE-2015-8333 | 1 Huawei | 1 Vcn500 | 2016-01-12 | 5.5 MEDIUM | 7.1 HIGH |
The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 allows remote authenticated users to change the IP address of the media server via crafted packets. | |||||
CVE-2015-8230 | 1 Huawei | 1 Espace 8950 | 2016-01-12 | 7.8 HIGH | 7.5 HIGH |
Memory leak in Huawei eSpace 8950 IP phones with software before V200R003C00SPC300 allows remote attackers to cause a denial of service (memory consumption and restart) via a large number of crafted ARP packets. | |||||
CVE-2015-8231 | 1 Huawei | 2 Espace 7910, Espace 7950 | 2016-01-12 | 7.8 HIGH | 7.5 HIGH |
Huawei eSpace 7910 and 7950 IP phones with software before V200R002C00SPC800 allow remote attackers with established sessions to cause a denial of service (device restart) via unspecified packets. | |||||
CVE-2015-8757 | 1 Typo3 | 1 Typo3 | 2016-01-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the Extension Manager in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to extension data during an extension installation. | |||||
CVE-2015-8756 | 1 Typo3 | 1 Typo3 | 2016-01-11 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in the search result view in the Indexed Search (indexed_search) component in TYPO3 6.2.x before 6.2.16 allows remote authenticated editors to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2015-8760 | 1 Typo3 | 1 Typo3 | 2016-01-11 | 4.3 MEDIUM | 6.1 MEDIUM |
The Flvplayer component in TYPO3 6.2.x before 6.2.16 allows remote attackers to embed Flash videos from external domains via unspecified vectors, aka "Cross-Site Flashing." | |||||
CVE-2015-8754 | 1 Acquia | 1 Mollom | 2016-01-11 | 5.0 MEDIUM | 7.5 HIGH |
The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and modify the mollom blacklist via unspecified vectors. | |||||
CVE-2015-8755 | 1 Typo3 | 1 Typo3 | 2016-01-11 | 3.5 LOW | 5.4 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allow remote authenticated editors to inject arbitrary web script or HTML via unknown vectors. | |||||
CVE-2016-1500 | 1 Owncloud | 1 Owncloud | 2016-01-11 | 3.5 LOW | 3.1 LOW |
ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share. | |||||
CVE-2016-1498 | 1 Owncloud | 1 Owncloud | 2016-01-11 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the OCS discovery provider component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a URL. | |||||
CVE-2016-1501 | 1 Owncloud | 1 Owncloud | 2016-01-11 | 4.0 MEDIUM | 4.3 MEDIUM |
ownCloud Server before 8.0.9 and 8.1.x before 8.1.4 allow remote authenticated users to obtain sensitive information via unspecified vectors, which reveals the installation path in the resulting exception messages. | |||||
CVE-2015-8761 | 1 Values Project | 1 Values | 2016-01-11 | 6.0 MEDIUM | 9.0 CRITICAL |
The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools import. | |||||
CVE-2015-8759 | 1 Typo3 | 1 Typo3 | 2016-01-11 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in the typoLink function in TYPO3 6.2.x before 6.2.16 and 7.x before 7.6.1 allows remote authenticated editors to inject arbitrary web script or HTML via a link field. |