Latest CVE Feed
-
5.9
MEDIUMCVE-2015-5316
The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon cra... Read more
- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2015-5315
The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when EAP-pwd is enabled in a network configuration profile, which allows remote attacke... Read more
- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2015-5314
The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used with (1) an internal EAP server or (2) a RADIUS server and EAP-pwd is enabl... Read more
- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-5298
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.... Read more
Affected Products : google_login- Published: Jul. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-5297
An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application using pixman to crash or, potentially, execute arbitrary code.... Read more
Affected Products : pixman- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-5290
A Denial of Service vulnerability exists in ircd-ratbox 3.0.9 in the MONITOR Command Handler.... Read more
Affected Products : ircd-ratbox- Published: Dec. 26, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-5278
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.... Read more
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-5243
phpWhois allows remote attackers to execute arbitrary code via a crafted whois record.... Read more
Affected Products : phpwhois- Published: Aug. 20, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-5239
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.... Read more
- Published: Jan. 23, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-5236
It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed ma... Read more
Affected Products : icedtea-web- Published: Jul. 07, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-5230
The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via crafted query packets.... Read more
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-5216
The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly escape certain characters in a Python exception-message template, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via an HTTP respo... Read more
Affected Products : ipsilon- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-5215
The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not enable auto-escaping, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via t... Read more
Affected Products : ipsilon- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-5201
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and ... Read more
- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-5160
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.... Read more
- Published: Aug. 20, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-5159
python-kdcproxy before 0.3.2 allows remote attackers to cause a denial of service via a large POST request.... Read more
Affected Products : kdcproxy- Published: Oct. 30, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-5079
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the dl parameter.... Read more
Affected Products : blackcat_cms- Published: Feb. 28, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-5072
The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary local files via the __imageid parameter.... Read more
Affected Products : remedy_ar_system_server- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-5071
AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary files via the __report parameter of the BIRT viewer servlet.... Read more
Affected Products : remedy_ar_system_server- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2015-5045
The Administration and Reporting tool in IBM Rational License Key Server (RLKS) before 8.1.4.9 iFix 04 allows local users to obtain sensitive information via unspecified vectors. IBM X-Force ID: 106938.... Read more
Affected Products : rational_license_key_server- Published: Mar. 26, 2018
- Modified: Nov. 21, 2024