Total
210374 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2015-3028 | 1 Mcafee | 1 Advanced Threat Defense | 2015-04-09 | 5.5 MEDIUM | N/A |
| McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to bypass intended restrictions and change or update configuration settings via crafted parameters. | |||||
| CVE-2015-3029 | 1 Mcafee | 1 Advanced Threat Defense | 2015-04-09 | 4.0 MEDIUM | N/A |
| The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 does not properly restrict access, which allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
| CVE-2015-2063 | 1 Winace | 1 Unace | 2015-04-09 | 4.3 MEDIUM | N/A |
| Integer overflow in unace 1.2b allows remote attackers to cause a denial of service (crash) via a small file header in an ace archive, which triggers a buffer overflow. | |||||
| CVE-2015-0876 | 1 Saurus | 1 Saurus Cms | 2015-04-07 | 4.3 MEDIUM | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in the print_language_selectbox function in classes/adminpage.inc.php in Saurus CMS Community Edition before 4.7 2015-02-04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
| CVE-2015-0951 | 1 Qualiteam | 1 X-cart | 2015-04-06 | 6.5 MEDIUM | N/A |
| X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2) remove request. | |||||
| CVE-2015-0950 | 1 Qualiteam | 1 X-cart | 2015-04-06 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script or HTML via the substring parameter. | |||||
| CVE-2015-0903 | 1 Hidemaru | 1 Editor | 2015-04-06 | 7.5 HIGH | N/A |
| Buffer overflow in Saitoh Kikaku Maruo Editor 8.51 and earlier allows remote attackers to execute arbitrary code via a crafted .hmbook file. | |||||
| CVE-2015-0877 | 1 C-board Moyuku Project | 1 C-board Moyuku | 2015-04-06 | 7.5 HIGH | N/A |
| Unrestricted file upload vulnerability in app/lib/mlf.pl in C-BOARD Moyuku before 1.03b3 allows remote attackers to execute arbitrary code by uploading a file with a \0 character in its name. | |||||
| CVE-2015-0119 | 1 Ibm | 1 Tivoli Storage Manager Fastback | 2015-04-06 | 7.5 HIGH | N/A |
| FastBack Mount in IBM Tivoli Storage Manager FastBack 6.1.x before 6.1.11.1 allows remote attackers to execute arbitrary code by connecting to the Mount port. | |||||
| CVE-2015-0994 | 1 Inductiveautomation | 1 Ignition | 2015-04-03 | 4.0 MEDIUM | N/A |
| Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by using different session ID values in a series of HTTP requests. | |||||
| CVE-2015-0995 | 1 Inductiveautomation | 1 Ignition | 2015-04-03 | 5.0 MEDIUM | N/A |
| Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to obtain access via a brute-force attack. | |||||
| CVE-2015-0993 | 1 Inductiveautomation | 1 Ignition | 2015-04-03 | 6.4 MEDIUM | N/A |
| Inductive Automation Ignition 7.7.2 does not terminate a session upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation. | |||||
| CVE-2015-0992 | 1 Inductiveautomation | 1 Ignition | 2015-04-03 | 2.1 LOW | N/A |
| Inductive Automation Ignition 7.7.2 stores cleartext OPC Server credentials, which allows local users to obtain sensitive information via unspecified vectors. | |||||
| CVE-2015-0991 | 1 Inductiveautomation | 1 Ignition | 2015-04-03 | 5.0 MEDIUM | N/A |
| Inductive Automation Ignition 7.7.2 allows remote attackers to obtain sensitive information by reading an error message about an unhandled exception, as demonstrated by pathname information. | |||||
| CVE-2015-0990 | 1 Ecava | 1 Integraxor | 2015-04-03 | 4.4 MEDIUM | N/A |
| Untrusted search path vulnerability in Ecava IntegraXor SCADA Server before 4.2.4488 allows local users to gain privileges via a renamed DLL in the default install directory. | |||||
| CVE-2015-0976 | 1 Inductiveautomation | 1 Ignition | 2015-04-03 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in Inductive Automation Ignition 7.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
| CVE-2015-0902 | 1 Semperfiwebdesign | 1 All In One Seo Pack | 2015-04-03 | 5.0 MEDIUM | N/A |
| The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protection during generation of the Meta Description field, which allows remote attackers to obtain sensitive information by reading HTML source code. | |||||
| CVE-2014-5400 | 1 Hospira | 1 Mednet | 2015-04-03 | 2.1 LOW | N/A |
| The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file. | |||||
| CVE-2014-5403 | 1 Hospira | 1 Mednet | 2015-04-03 | 5.0 MEDIUM | N/A |
| Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network. | |||||
| CVE-2012-2808 | 1 Google | 1 Bionic | 2015-04-01 | 5.0 MEDIUM | N/A |
| The PRNG implementation in the DNS resolver in Bionic in Android before 4.1.1 incorrectly uses time and PID information during the generation of random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2015-0800. | |||||
