Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-0665 | 1 Cisco | 1 Anyconnect Secure Mobility Client | 2015-10-27 | 6.6 MEDIUM | N/A |
The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary files via crafted IPC messages, aka Bug ID CSCus79173. | |||||
CVE-2015-0682 | 1 Cisco | 1 Unified Communications Domain Manager | 2015-10-27 | 6.5 MEDIUM | N/A |
Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka Bug ID CSCup90168. | |||||
CVE-2015-1165 | 3 Bestpractical, Debian, Fedoraproject | 3 Request Tracker, Debian Linux, Fedora | 2015-10-27 | 5.0 MEDIUM | N/A |
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors. | |||||
CVE-2015-1464 | 2 Bestpractical, Fedoraproject | 2 Request Tracker, Fedora | 2015-10-27 | 6.4 MEDIUM | N/A |
RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL. | |||||
CVE-2015-5665 | 1 Lockon | 1 Ec-cube | 2015-10-27 | 5.1 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijack the authentication of arbitrary users for requests that write to PHP scripts, related to the doValidToken function. | |||||
CVE-2013-3672 | 1 Ffmpeg | 1 Ffmpeg | 2015-10-27 | 4.3 MEDIUM | N/A |
The mm_decode_inter function in mmvideo.c in libavcodec in FFmpeg before 1.2.1 does not validate the relationship between a horizontal coordinate and a width value, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted American Laser Games (ALG) MM Video data. | |||||
CVE-2013-3674 | 1 Ffmpeg | 1 Ffmpeg | 2015-10-27 | 4.3 MEDIUM | N/A |
The cdg_decode_frame function in cdgraphics.c in libavcodec in FFmpeg before 1.2.1 does not validate the presence of non-header data in a buffer, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted CD Graphics Video data. | |||||
CVE-2015-5193 | 2015-10-26 | N/A | N/A | ||
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7703. Reason: This candidate is a reservation duplicate of CVE-2015-7703. Notes: All CVE users should reference CVE-2015-7703 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | |||||
CVE-2015-5014 | 1 Ibm | 1 Cognos Disclosure Management | 2015-10-26 | 9.3 HIGH | N/A |
IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an executable file during a client upload operation. | |||||
CVE-2015-5011 | 1 Ibm | 2 Integration Bus, Websphere Message Broker | 2015-10-26 | 3.2 LOW | N/A |
IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command. | |||||
CVE-2015-6484 | 1 3s-smart Software Solutions | 1 Codesys Gateway Server | 2015-10-26 | 5.0 MEDIUM | N/A |
3S-Smart CODESYS Gateway Server before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted (1) GET or (2) POST request. | |||||
CVE-2015-1005 | 1 Ininet Solutions | 1 Scada Web Server | 2015-10-26 | 2.1 LOW | N/A |
IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2015-1003 | 1 Ininet Solutions | 1 Scada Web Server | 2015-10-26 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname. | |||||
CVE-2015-1002 | 1 Ininet Solutions | 1 Scada Web Server | 2015-10-26 | 6.4 MEDIUM | N/A |
IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string. | |||||
CVE-2015-7003 | 1 Apple | 1 Mac Os X | 2015-10-26 | 6.8 MEDIUM | N/A |
coreaudiod in Audio in Apple OS X before 10.11.1 does not initialize an unspecified data structure, which allows attackers to execute arbitrary code via a crafted app. | |||||
CVE-2015-6987 | 1 Apple | 1 Mac Os X | 2015-10-26 | 2.1 LOW | N/A |
The File Bookmark component in Apple OS X before 10.11.1 allows local users to cause a denial of service (application crash) via crafted bookmark metadata in a folder. | |||||
CVE-2015-6985 | 1 Apple | 1 Mac Os X | 2015-10-26 | 6.8 MEDIUM | N/A |
Apple Type Services (ATS) in Apple OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web page. | |||||
CVE-2015-7021 | 1 Apple | 1 Mac Os X | 2015-10-26 | 7.2 HIGH | N/A |
The Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to gain privileges or cause a denial of service (kernel memory corruption) via unspecified vectors. | |||||
CVE-2015-5945 | 1 Apple | 1 Mac Os X | 2015-10-26 | 7.2 HIGH | N/A |
The Sandbox subsystem in Apple OS X before 10.11.1 allows local users to gain privileges via vectors involving NVRAM parameters. | |||||
CVE-2015-7020 | 1 Apple | 1 Mac Os X | 2015-10-26 | 5.6 MEDIUM | N/A |
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via unspecified vectors, a different vulnerability than CVE-2015-7019. |