Total
210374 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2015-0926 | 1 Labtech Software | 1 Labtech | 2015-02-03 | 6.8 MEDIUM | N/A |
| Labtech before 100.237 on Linux uses world-writable permissions for root-executed scripts, which allows local users to gain privileges by modifying a script file. | |||||
| CVE-2015-0870 | 1 Nishishi | 1 Fumy News Clipper | 2015-02-02 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in hb.cgi in Nishishi Factory Fumy News Clipper 2.x before 2.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
| CVE-2015-0868 | 1 Shiromuku | 1 Bu2 Bbs | 2015-02-02 | 7.5 HIGH | N/A |
| Unrestricted file upload vulnerability in Mrs. Shiromuku Perl CGI shiromuku(bu2)BBS before 2.91 allows remote attackers to execute arbitrary code by uploading an executable file. | |||||
| CVE-2014-8268 | 1 Qpr | 1 Portal | 2015-02-02 | 6.4 MEDIUM | N/A |
| QPR Portal before 2012.2.1 allows remote attackers to modify or delete notes via a direct request. | |||||
| CVE-2014-8267 | 1 Qpr | 1 Portal | 2015-02-02 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the RID parameter. | |||||
| CVE-2014-8266 | 1 Qpr | 1 Portal | 2015-02-02 | 4.3 MEDIUM | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in the note-creation page in QPR Portal 2014.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) body field. | |||||
| CVE-2014-7266 | 1 Cybozu | 1 Remote Service Manager | 2015-02-02 | 7.8 HIGH | N/A |
| Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a denial of service (CPU consumption) via vectors that trigger colliding hash-table keys. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1983. | |||||
| CVE-2014-8511 | 1 Schneider-electric | 1 Proclima | 2015-02-02 | 10.0 HIGH | N/A |
| Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8512. NOTE: this may be clarified later based on details provided by researchers. | |||||
| CVE-2014-4467 | 1 Apple | 1 Iphone Os | 2015-02-02 | 4.3 MEDIUM | N/A |
| WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAME elements, which allows remote attackers to spoof the UI via a crafted web site. | |||||
| CVE-2015-1370 | 1 Marked Project | 1 Marked | 2015-01-28 | 4.3 MEDIUM | N/A |
| Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link. | |||||
| CVE-2015-1369 | 1 Sequelize Project | 1 Sequelize | 2015-01-28 | 7.5 HIGH | N/A |
| SQL injection vulnerability in Sequelize before 2.0.0-rc7 for Node.js allows remote attackers to execute arbitrary SQL commands via the order parameter. | |||||
| CVE-2014-9197 | 1 Schneider-electric | 5 Etg3000 Factorycast Hmi Gateway Firmware, Tsxetg3000, Tsxetg3010 and 2 more | 2015-01-28 | 7.8 HIGH | N/A |
| The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request. | |||||
| CVE-2015-1362 | 1 Two Pilots | 1 Exif Pilot | 2015-01-28 | 7.5 HIGH | N/A |
| Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary code via a long string in the maker element in an XML file. | |||||
| CVE-2014-5211 | 1 Attachmate | 1 Reflection Ftp Client | 2015-01-28 | 6.8 MEDIUM | N/A |
| Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response. | |||||
| CVE-2015-1363 | 1 Freereprintables | 1 Articlefr | 2015-01-28 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in Free Reprintables ArticleFR 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter to search/v/. | |||||
| CVE-2015-1364 | 1 Freereprintables | 1 Articlefr | 2015-01-28 | 7.5 HIGH | N/A |
| SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter to register/. | |||||
| CVE-2015-1371 | 1 Ferretcms Project | 1 Ferretcms | 2015-01-27 | 7.5 HIGH | N/A |
| Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in custom/uploads/. | |||||
| CVE-2015-1372 | 1 Ferretcms Project | 1 Ferretcms | 2015-01-27 | 7.5 HIGH | N/A |
| SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p parameter in an update action to admin.php. | |||||
| CVE-2015-1373 | 1 Ferretcms Project | 1 Ferretcms | 2015-01-27 | 4.3 MEDIUM | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter in a search request, (2) username in a login request, which is not properly handled when logging the event, or (3) page title in an insert action. | |||||
| CVE-2015-1374 | 1 Ferretcms Project | 1 Ferretcms | 2015-01-27 | 6.8 MEDIUM | N/A |
| Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to hijack the authentication of administrators for requests that conduct (1) cross-site scripting (XSS), (2) SQL injection, or (3) unrestricted file upload attacks. | |||||
