Latest CVE Feed
-
7.5
HIGHCVE-2015-8547
The CoreUserInputHandler::doMode function in core/coreuserinputhandler.cpp in Quassel 0.10.0 allows remote attackers to cause a denial of service (application crash) via the "/op *" command in a query.... Read more
- EPSS Score: %2.36
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-8481
Atlassian JIRA Software 7.0.3, JIRA Core 7.0.3, and the bundled JIRA Service Desk 3.0.3 installer attaches the wrong image to e-mail notifications when a user views an issue with inline wiki markup referencing an image attachment, which might allow remote... Read more
- EPSS Score: %0.21
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-8303
Huawei Document Security Management (DSM) with software before V100R002C05SPC661 does not clear the clipboard when closing a secure file, which allows local users to obtain sensitive information by pasting the contents to another file.... Read more
Affected Products : document_security_management- EPSS Score: %0.02
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-8226
The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL00C00B220 and ALE-TL00C01B220 and GEM-703L smartphones with software before V100R001C233B111 allows remote attackers to cause a denial o... Read more
- EPSS Score: %0.12
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-8225
The Joint Photographic Experts Group Processing Unit (JPU) driver in Huawei ALE smartphones with software before ALE-UL00C00B220 and ALE-TL00C01B220 and GEM-703L smartphones with software before V100R001C233B111 allows remote attackers to cause a denial o... Read more
- EPSS Score: %0.12
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
3.3
LOWCVE-2015-7758
Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .toc extension for the file name, as demonstrated by .thesi... Read more
- EPSS Score: %0.05
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-7754
Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or execute arbitrary code via crafted SSH negotiation.... Read more
Affected Products : screenos- EPSS Score: %2.94
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-7554
The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image.... Read more
Affected Products : libtiff- EPSS Score: %0.50
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7519
agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote attackers to spoof headers passed to applications by usin... Read more
- EPSS Score: %0.44
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-7362
Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable and executable, allows local users to gain privileges via the helper/subroc setuid program.... Read more
Affected Products : forticlient- EPSS Score: %0.04
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
4.7
MEDIUMCVE-2015-7328
Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permissions for the private key of the Certification Authority (CA) certificate during the initial installation and configuration, which might al... Read more
Affected Products : puppet_enterprise- EPSS Score: %0.03
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6856
Dell Pre-Boot Authentication Driver (PBADRV.sys) 1.0.1.5 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x0022201c IOCTL call.... Read more
Affected Products : pre-boot_authentication_driver- EPSS Score: %0.08
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-5259
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-boun... Read more
Affected Products : subversion- EPSS Score: %40.68
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-5254
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.... Read more
- EPSS Score: %80.39
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1131
Buffer overflow in the CL_vsprintf function in Takumi Yamada DX Library before 3.16 allows remote attackers to execute arbitrary code via a crafted string.... Read more
Affected Products : dx_library- EPSS Score: %1.39
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-8261
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.... Read more
- EPSS Score: %4.36
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
8.4
HIGHCVE-2015-6862
HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.... Read more
Affected Products : ucmdb_browser- EPSS Score: %0.47
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-6434
Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue... Read more
Affected Products : prime_infrastructure- EPSS Score: %0.24
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-6433
SQL injection vulnerability in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCut66767.... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.16
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-6647
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24441554.... Read more
Affected Products : android- EPSS Score: %0.17
- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025