Latest CVE Feed
-
5.0
MEDIUMCVE-2014-9756
The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable.... Read more
- EPSS Score: %0.66
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-8236
Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to execute arbitrary code as root by leveraging management-plane access, aka Bug 138716.... Read more
Affected Products : eos- EPSS Score: %6.02
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-7910
Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass intended access restrictions by disregarding this header and processing the response body.... Read more
Affected Products : telemetry_web_server- EPSS Score: %0.26
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4112
The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site, related to a "cross frame scri... Read more
Affected Products : enterprise_server- EPSS Score: %0.22
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6374
The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attac... Read more
- EPSS Score: %0.22
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-6371
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621.... Read more
- EPSS Score: %0.18
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-6370
The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows local users to execute arbitrary OS commands as root via crafted CLI input, aka Bug ID CSCux10578.... Read more
- EPSS Score: %0.32
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-6369
The USB driver in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows physically proximate attackers to cause a denial of service via a crafted USB device that triggers invalid USB commands, aka Bug ID CSCux10531.... Read more
- EPSS Score: %0.10
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6368
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608.... Read more
- EPSS Score: %0.08
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-8090
The Web Server component in TIBCO LogLogic Unity before 1.1.1 allows remote authenticated users to gain privileges, and consequently obtain sensitive information, via an HTTP request.... Read more
Affected Products : loglogic_unity- EPSS Score: %0.14
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8053
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8052.... Read more
Affected Products : coldfusion- EPSS Score: %0.75
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8052
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8053.... Read more
Affected Products : coldfusion- EPSS Score: %0.75
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-8051
The Adobe Premiere Clip app before 1.2.1 for iOS mishandles unspecified input, which has unknown impact and attack vectors.... Read more
Affected Products : premiere_clip- EPSS Score: %4.58
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5255
Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows... Read more
- EPSS Score: %2.90
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-8035
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.... Read more
- EPSS Score: %1.05
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-8023
The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in ... Read more
- EPSS Score: %0.80
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-7942
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via craf... Read more
Affected Products : ubuntu_linux debian_linux libxml2 mac_os_x iphone_os tvos watchos icewall_federation_agent icewall_file_manager- EPSS Score: %1.16
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7941
libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections ... Read more
- EPSS Score: %1.45
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5999
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2)... Read more
- EPSS Score: %16.44
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-5253
The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."... Read more
Affected Products : cxf- EPSS Score: %0.34
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025