Latest CVE Feed
-
4.3
MEDIUMCVE-2015-1971
Unspecified vulnerability in Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF8 and 5.x before 5.0.2 IF10; Rational Quality Manager (RQM) 2.x and 3.x before 3.0.1.6 IF7, 4.x before 4.0... Read more
- EPSS Score: %0.25
- Published: Jan. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8027
Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP ... Read more
Affected Products : node.js- EPSS Score: %1.50
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7452
IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow remote authenticated users to obtain sensitive informatio... Read more
- EPSS Score: %0.16
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-7450
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransf... Read more
- Actively Exploited
- EPSS Score: %93.83
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
4.7
MEDIUMCVE-2015-7438
IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive cleartext web-services information by leveraging database access.... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.04
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-7437
Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.04
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
2.5
LOWCVE-2015-7436
IBM Tivoli Common Reporting (TCR) 2.1 before IF14, 2.1.1 before IF22, 2.1.1.2 before IF9, 3.1.0.0 through 3.1.2 as used in Cognos Business Intelligence before 10.2 IF16, and 3.1.2.1 as used in Cognos Business Intelligence before 10.2.1.1 IF12 preserves us... Read more
Affected Products : tivoli_common_reporting- EPSS Score: %0.04
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
2.5
LOWCVE-2015-7435
IBM Tivoli Common Reporting (TCR) 2.1 before IF14, 2.1.1 before IF22, 2.1.1.2 before IF9, 3.1.0.0 through 3.1.2 as used in Cognos Business Intelligence before 10.2 IF16, and 3.1.2.1 as used in Cognos Business Intelligence before 10.2.1.1 IF12 allows local... Read more
Affected Products : tivoli_common_reporting- EPSS Score: %0.05
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-7431
Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.22
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
8.4
HIGHCVE-2015-7430
The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to read or write to arbitrary GPFS data via unspecified vectors.... Read more
- EPSS Score: %0.05
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
10.0
CRITICALCVE-2015-7426
The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.3.0 and Tivoli Storage FlashCopy Manager for VMware (aka Spec... Read more
- EPSS Score: %2.73
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-7422
Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via unspecified vectors.... Read more
- EPSS Score: %0.08
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-7416
AFP Workbench Viewer in IBM i Access 7.1 on Windows allows remote attackers to cause a denial of service (viewer crash) via a crafted workbench file.... Read more
- EPSS Score: %0.22
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2015-7407
Cross-site request forgery (CSRF) vulnerability in Lotus Mashups in IBM Mashup Center 3.0.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.... Read more
Affected Products : mashups_center- EPSS Score: %0.11
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-7403
IBM Spectrum Scale 4.1.1.x before 4.1.1.3 and General Parallel File System (GPFS) 3.5.x before 3.5.0.29 and 4.1.x through 4.1.0.8 on AIX allow local users to cause a denial of service (incorrect pointer dereference and node crash) via unspecified vectors.... Read more
- EPSS Score: %0.06
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
7.7
HIGHCVE-2015-7400
The Lotus Mashups component in IBM Mashup Center 3.0.0.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XX... Read more
Affected Products : mashups_center- EPSS Score: %0.77
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-7396
The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.1 FP1 for SmartCloud Control Desk allows remote authenticated users to bypass in... Read more
- EPSS Score: %0.13
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2015-2023
Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors.... Read more
- EPSS Score: %0.16
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1928
Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and 6.x before 6.0.0 IF4; Rational Quality Manager (RQM) 3.x before 3.0.1.6 IF7, 4.x before 4.0.7 IF9, 5.x be... Read more
- EPSS Score: %0.30
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2015-7451
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5 before 7.5.0.9 IF2 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 IF2, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allows remote authe... Read more
- EPSS Score: %0.17
- Published: Jan. 02, 2016
- Modified: Apr. 12, 2025