Latest CVE Feed
-
8.8
HIGHCVE-2015-8371
Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The issue occurs because of the way that dist packages are cached. The cache key i... Read more
Affected Products : composer- Published: Sep. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-8367
The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.... Read more
Affected Products : libraw- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-8366
Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.... Read more
Affected Products : libraw- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
5.9
MEDIUM- Published: Dec. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-8298
Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands via the (1) loginpassword, (2) loginusername, (3) zusatzlicher, or (4) groupid parameter to index.htm, or t... Read more
Affected Products : rxadmin- Published: Sep. 24, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-8094
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.... Read more
Affected Products : hue- Published: May. 22, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2015-8033
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.... Read more
Affected Products : textpattern- Published: Aug. 14, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2015-8032
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.... Read more
Affected Products : textpattern- Published: Aug. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-8031
Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks.... Read more
Affected Products : hudson- Published: Jul. 18, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-8012
lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malformed packet.... Read more
Affected Products : lldpd- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-8011
Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV b... Read more
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2015-7968
nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.... Read more
- Published: Mar. 09, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-7967
SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.... Read more
Affected Products : safenet_authentication_service_for_citrix_web_interface_agent- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-7966
SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7965... Read more
Affected Products : safenet_authentication_service_windows_logon_agent- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-7965
SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7966... Read more
Affected Products : safenet_authentication_service_windows_logon_agent- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-7964
SafeNet Authentication Service for NPS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.... Read more
Affected Products : safenet_authentication_service_for_nps_agent- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-7963
SafeNet Authentication Service for AD FS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.... Read more
Affected Products : safenet_authentication_service_for_ad_fs_agent- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-7962
SafeNet Authentication Service for Outlook Web App Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.... Read more
Affected Products : safenet_authentication_service_for_outlook_web_app_agent- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-7961
SafeNet Authentication Service Remote Web Workplace Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.... Read more
Affected Products : safenet_authentication_service_remote_web_workplace_agent- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2015-7946
Information Exposure vulnerability in Unity8 as used on the Ubuntu phone and possibly also in Unity8 shipped elsewhere. This allows an attacker to enable the MTP service by opening the emergency dialer. Fixed in 8.11+16.04.20160111.1-0ubuntu1 and 8.11+15.... Read more
Affected Products : unity8- Published: May. 07, 2020
- Modified: Nov. 21, 2024