Latest CVE Feed
-
5.9
MEDIUMCVE-2015-0897
LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by ... Read more
- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-0841
Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attackers to cause a denial of service (crash) via a long line.... Read more
Affected Products : monopd- Published: Dec. 09, 2019
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2015-0837
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Sid... Read more
- Published: Nov. 29, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2015-0796
In open buildservice 2.6 before 2.6.3, 2.5 before 2.5.7 and 2.4 before 2.4.8 the source service patch application could generate non-standard files like symlinks or device nodes, which could allow buildservice users to break of confinement or cause denial... Read more
- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2015-0749
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters ... Read more
Affected Products : unified_communications_manager- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2015-0565
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.... Read more
Affected Products : native_client- Published: Feb. 25, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2015-0558
The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6, and possibly other routers, uses "1236790" and the MAC address to generate the WPA key.... Read more
- Published: Jan. 14, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-0294
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-0270
Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.... Read more
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-0258
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtm... Read more
- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-0244
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted bin... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-0243
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbi... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-0242
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to c... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-0241
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) larg... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2015-0203
The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a sequence set, (2) content-bearing methods other than message-transfer, or (3)... Read more
Affected Products : qpid- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-0172
IBM Security SiteProtector System 3.0, 3.1.0 and 3.1.1 allows remote attackers to bypass intended security restrictions and consequently execute unspecified commands and obtain sensitive information via unknown vectors. IBM X-Force ID: 100927.... Read more
Affected Products : security_siteprotector_system- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2015-0153
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the wireless key.... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-0152
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage of the administrative password.... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2015-0151
Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-0150
The remote administration UI in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to bypass intended access restrictions via unspecified vectors.... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024