Latest CVE Feed
-
7.5
HIGHCVE-2015-4514
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.... Read more
- EPSS Score: %1.85
- Published: Nov. 05, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-4513
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via... Read more
- EPSS Score: %2.02
- Published: Nov. 05, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-7650
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to execute arbitrary ... Read more
- EPSS Score: %1.02
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-7253
The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie.... Read more
Affected Products : edge_server- EPSS Score: %0.81
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-7244
The default configuration of the server in MobaXterm before 8.3 has a disabled Access Control setting and consequently does not require authentication for X11 connections, which allows remote attackers to execute arbitrary commands or obtain sensitive inf... Read more
Affected Products : mobaxterm- EPSS Score: %5.18
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6867
The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to execute arbitrary commands via a crafted packet, aka ZDI-CAN-2914.... Read more
Affected Products : vertica- EPSS Score: %5.68
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6356
Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco Social Miner 10.0(1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuw60212.... Read more
Affected Products : socialminer- EPSS Score: %0.40
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6355
The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226.... Read more
- EPSS Score: %0.47
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-6030
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight ... Read more
- EPSS Score: %0.98
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6029
HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.... Read more
Affected Products : arcsight_logger- EPSS Score: %10.17
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-5673
eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper popen calls, which allows remote attackers to execute arbitrary commands via an HTTP request that includes shell metacharacters in an ar... Read more
Affected Products : isucon_5_qualifier_eventapp- EPSS Score: %0.52
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-5021
IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors.... Read more
Affected Products : infosphere_information_server- EPSS Score: %0.25
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-4927
The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses world-writable permissions for unspecified files, which allows local users to gain privileges by writing ... Read more
Affected Products : tivoli_storage_manager- EPSS Score: %0.11
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-2903
The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password.... Read more
Affected Products : arcsight_smartconnectors- EPSS Score: %3.21
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2902
HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate.... Read more
Affected Products : arcsight_smartconnectors- EPSS Score: %0.95
- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-8074
mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23540907 and 23515142, a different vulnerability than C... Read more
Affected Products : android- EPSS Score: %0.07
- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-8073
mediaserver in Android 4.4 and 5.1 before 5.1.1 LMY48X allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 14388161, a different vulnerability than CVE-2015-6608 and... Read more
Affected Products : android- EPSS Score: %3.76
- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-8072
mediaserver in Android 4.4 through 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23881715, a different vulner... Read more
Affected Products : android- EPSS Score: %3.76
- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-6614
Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently bypass intended network-interface restrictions, perform expensive data transfers, or cause a denial of service (call-reception outage or mute manipulation),... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
5.1
MEDIUMCVE-2015-6613
Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port, and consequently gain privileges, via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka ... Read more
Affected Products : android- EPSS Score: %0.14
- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025