Latest CVE Feed
-
8.8
HIGHCVE-2015-1784
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the application validates user uploaded files and lack of security me... Read more
Affected Products : nextgen_gallery- Published: Jul. 07, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-1780
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center... Read more
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2015-1777
rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not properly validate hostnames in X.509 certificates from SSL servers, which allows remote attackers to prevent s... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-1607
kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related t... Read more
- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-1606
The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a crafted keyring file.... Read more
- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-1583
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php or (2)... Read more
Affected Products : atutor- Published: Mar. 02, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-1530
media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_server privileges or cause a denial of service (integer overflow) via a crafted application that provides an invalid array size.... Read more
Affected Products : android- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-1525
audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted application that provides a NULL device address.... Read more
Affected Products : android- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-1503
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot)... Read more
Affected Products : mail_server- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-1425
JAKWEB Gecko CMS has Multiple Input Validation Vulnerabilities... Read more
Affected Products : gecko_cms- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-1418
The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1 before 10.2-RC1-p2, and 0.2-RC2 before 10.2-RC2-p1, allows remote attackers to execute arbitrary commands... Read more
Affected Products : freebsd- Published: Feb. 05, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-1416
Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5; and possibly other patch variants allow remote attackers to execute arbitrary shell commands via... Read more
Affected Products : freebsd- Published: Feb. 05, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-1396
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.... Read more
- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2015-1394
Multiple cross-site scripting (XSS) vulnerabilities in the Photo Gallery plugin before 1.2.11 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the (1) sort_by, (2) sort_order, (3) items_view, (4) dir, (5) clipboard... Read more
Affected Products : photo_gallery- Published: Feb. 08, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-1391
Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.... Read more
Affected Products : airwave- Published: Sep. 05, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-1390
Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.... Read more
Affected Products : airwave- Published: Sep. 05, 2023
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2015-1343
All versions of unity-scope-gdrive logs search terms to syslog.... Read more
Affected Products : ubuntu_linux- Published: Apr. 22, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-1341
Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.... Read more
- Published: Apr. 22, 2019
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2015-1340
LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's... Read more
Affected Products : lxd- Published: Apr. 22, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-1327
Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transfer. This could allow a malicious application using the D... Read more
Affected Products : ubuntu_linux- Published: Apr. 22, 2019
- Modified: Nov. 21, 2024