Latest CVE Feed
-
4.3
MEDIUMCVE-2015-8052
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8053.... Read more
Affected Products : coldfusion- EPSS Score: %0.75
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-8051
The Adobe Premiere Clip app before 1.2.1 for iOS mishandles unspecified input, which has unknown impact and attack vectors.... Read more
Affected Products : premiere_clip- EPSS Score: %4.58
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5255
Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows... Read more
- EPSS Score: %2.90
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-8035
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.... Read more
- EPSS Score: %1.05
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-8023
The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly validate local state, which allows remote attackers to bypass authentication via an empty Success message in ... Read more
- EPSS Score: %0.80
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-7942
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via craf... Read more
Affected Products : ubuntu_linux debian_linux libxml2 mac_os_x iphone_os tvos watchos icewall_federation_agent icewall_file_manager- EPSS Score: %1.16
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7941
libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections ... Read more
- EPSS Score: %1.45
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5999
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2.06.B09_BETA allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2)... Read more
- EPSS Score: %16.44
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-5253
The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."... Read more
Affected Products : cxf- EPSS Score: %0.34
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-6373
Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCux10611.... Read more
- EPSS Score: %0.12
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6372
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ... Read more
- EPSS Score: %0.30
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-4852
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/mo... Read more
Affected Products : weblogic_server storagetek_tape_analytics_sw_tool virtual_desktop_infrastructure- Actively Exploited
- EPSS Score: %92.68
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-6847
The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 before P3 stores cleartext NAVISPHERE GUI passwords in a log file, which allows local users to obtain sensitive information by reading this file.... Read more
Affected Products : vplex_geosynchrony- EPSS Score: %0.06
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-6357
The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide an invalid pack... Read more
Affected Products : firesight_system_software- EPSS Score: %5.94
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-6330
Cross-site request forgery (CSRF) vulnerability in Cisco Prime Collaboration Assurance 10.5(1) and 10.6 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus62712.... Read more
Affected Products : prime_collaboration_assurance- EPSS Score: %0.12
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-8233
Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.6 for Drupal allows remote administrators with the "Administer themes" permission to inject arbitrary web script or HTML via unspecified vectors rel... Read more
Affected Products : mayo- EPSS Score: %0.32
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8232
The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstances, which might allow remote attackers to obtain sensitive information from the anonymous user profile via unspecified vectors.... Read more
Affected Products : uc_profile- EPSS Score: %0.25
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2015-8222
The lxd-unix.socket systemd unit file in the Ubuntu lxd package before 0.20-0ubuntu4.1 uses world-readable permissions for /var/lib/lxd/unix.socket, which allows local users to gain privileges via unspecified vectors.... Read more
Affected Products : ubuntu_linux- EPSS Score: %0.12
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-8221
Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, which triggers a heap-based buffer overflow.... Read more
Affected Products : picasa- EPSS Score: %24.93
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8220
Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link.... Read more
Affected Products : dameware_mini_remote_control- EPSS Score: %9.39
- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025