Latest CVE Feed
-
6.6
MEDIUMCVE-2015-8328
Unspecified vulnerability in the NVAPI support layer in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows allows local users to obtain sensitive information, cause a denial of service (crash), or poss... Read more
- EPSS Score: %0.05
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-8229
Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow remote authenticated users to cause a denial of service via crafted signaling packets from a registered device.... Read more
- EPSS Score: %0.19
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-8228
Directory traversal vulnerability in the SFTP server in Huawei AR 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600 routers with software before V200R006SPH003 allows remote authenticated users to access arbitrary directories via unspecified vectors.... Read more
- EPSS Score: %0.54
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
8.5
HIGHCVE-2015-8227
The built-in web server in Huawei VP9660 multi-point control unit with software before V200R001C30SPC700 allows remote administrators to obtain sensitive information or cause a denial of service via a crafted message.... Read more
- EPSS Score: %0.16
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-7985
Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan horse steam.exe file.... Read more
- EPSS Score: %0.14
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-7981
The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an... Read more
- EPSS Score: %0.79
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
6.6
MEDIUMCVE-2015-7869
Multiple integer overflows in the kernel mode driver for the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows and R304 before 304.131, R340 before 340.96, R352 before 352.63, and R358 before 358.16 on Li... Read more
- EPSS Score: %0.06
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-7866
Unquoted Windows search path vulnerability in the Smart Maximize Helper (nvSmartMaxApp.exe) in the Control Panel in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows allows local users to gain privile... Read more
- EPSS Score: %0.07
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
7.7
HIGHCVE-2015-7865
nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows does not properly restrict access to the stereosvrpipe named pipe, which allows local users t... Read more
- EPSS Score: %2.11
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-7808
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/d... Read more
Affected Products : vbulletin- EPSS Score: %84.78
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-7496
GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.... Read more
- EPSS Score: %0.08
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-5281
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the co... Read more
Affected Products : enterprise_linux- EPSS Score: %0.06
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-5053
The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attack... Read more
Affected Products : gpu_driver- EPSS Score: %0.52
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2015-0856
daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.... Read more
- EPSS Score: %0.17
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-6380
An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to execute arbitrary OS commands via crafted parameters, aka Bug ID CSCux10622.... Read more
- EPSS Score: %0.45
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6377
Cisco Virtual Topology System (VTS) 2.0(0) and 2.0(1) allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP port outage) via a flood of crafted TCP packets, aka Bug ID CSCux13379.... Read more
Affected Products : virtual_topology_system- EPSS Score: %3.55
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-8320
Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge hijacking attacks by predicting a value.... Read more
Affected Products : cordova- EPSS Score: %2.56
- Published: Nov. 23, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5256
Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended access restrictions via a crafted URI.... Read more
Affected Products : cordova- EPSS Score: %0.70
- Published: Nov. 23, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5451
Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.... Read more
Affected Products : operations_orchestration- EPSS Score: %0.11
- Published: Nov. 23, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-7036
The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a SQL command that triggers an API call with a crafted p... Read more
- EPSS Score: %3.07
- Published: Nov. 22, 2015
- Modified: Apr. 12, 2025