Latest CVE Feed
-
7.8
HIGHCVE-2015-0949
The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revision L71 Ver. 01.09, and possibly other BIOS implementations does not ensure that function calls operate on SMRAM memory locations, whic... Read more
Affected Products : elitebook_850_g1_firmware elitebook_850_g1 latitude_e6430_firmware latitude_e6430- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2015-0897
LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by ... Read more
- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-0841
Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attackers to cause a denial of service (crash) via a long line.... Read more
Affected Products : monopd- Published: Dec. 09, 2019
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2015-0837
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Sid... Read more
- Published: Nov. 29, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-0796
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to break of confinement or cause denial... Read more
- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-0749
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters ... Read more
Affected Products : unified_communications_manager- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2015-0565
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.... Read more
Affected Products : native_client- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2015-0558
The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6, and possibly other routers, uses "1236790" and the MAC address to generate the WPA key.... Read more
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-0294
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-0270
Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.... Read more
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-0258
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtm... Read more
- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-0244
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted bin... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-0243
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbi... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-0242
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to c... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-0241
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) larg... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-0203
The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a sequence set, (2) content-bearing methods other than message-transfer, or (3)... Read more
Affected Products : qpid- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-0172
IBM Security SiteProtector System 3.0, 3.1.0 and 3.1.1 allows remote attackers to bypass intended security restrictions and consequently execute unspecified commands and obtain sensitive information via unknown vectors. IBM X-Force ID: 100927.... Read more
Affected Products : security_siteprotector_system- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-0153
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the wireless key.... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-0152
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the administrative password.... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-0151
Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024