Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2015-6355

    The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226.... Read more

    • EPSS Score: %0.47
    • Published: Nov. 04, 2015
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2015-6030

    HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight ... Read more

    • EPSS Score: %0.98
    • Published: Nov. 04, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-6029

    HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.... Read more

    Affected Products : arcsight_logger
    • EPSS Score: %10.17
    • Published: Nov. 04, 2015
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2015-5673

    eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper popen calls, which allows remote attackers to execute arbitrary commands via an HTTP request that includes shell metacharacters in an ar... Read more

    Affected Products : isucon_5_qualifier_eventapp
    • EPSS Score: %0.52
    • Published: Nov. 04, 2015
    • Modified: Apr. 12, 2025
  • 5.5

    MEDIUM
    CVE-2015-5021

    IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors.... Read more

    Affected Products : infosphere_information_server
    • EPSS Score: %0.25
    • Published: Nov. 04, 2015
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2015-4927

    The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses world-writable permissions for unspecified files, which allows local users to gain privileges by writing ... Read more

    Affected Products : tivoli_storage_manager
    • EPSS Score: %0.11
    • Published: Nov. 04, 2015
    • Modified: Apr. 12, 2025
  • 6.9

    MEDIUM
    CVE-2015-2903

    The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password.... Read more

    Affected Products : arcsight_smartconnectors
    • EPSS Score: %3.21
    • Published: Nov. 04, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-2902

    HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate.... Read more

    Affected Products : arcsight_smartconnectors
    • EPSS Score: %0.95
    • Published: Nov. 04, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-8074

    mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23540907 and 23515142, a different vulnerability than C... Read more

    Affected Products : android
    • EPSS Score: %0.07
    • Published: Nov. 03, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-8073

    mediaserver in Android 4.4 and 5.1 before 5.1.1 LMY48X allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 14388161, a different vulnerability than CVE-2015-6608 and... Read more

    Affected Products : android
    • EPSS Score: %3.76
    • Published: Nov. 03, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-8072

    mediaserver in Android 4.4 through 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23881715, a different vulner... Read more

    Affected Products : android
    • EPSS Score: %3.76
    • Published: Nov. 03, 2015
    • Modified: Apr. 12, 2025
  • 5.8

    MEDIUM
    CVE-2015-6614

    Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently bypass intended network-interface restrictions, perform expensive data transfers, or cause a denial of service (call-reception outage or mute manipulation),... Read more

    Affected Products : android
    • EPSS Score: %0.05
    • Published: Nov. 03, 2015
    • Modified: Apr. 12, 2025
  • 5.1

    MEDIUM
    CVE-2015-6613

    Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port, and consequently gain privileges, via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka ... Read more

    Affected Products : android
    • EPSS Score: %0.14
    • Published: Nov. 03, 2015
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2015-6612

    libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges via a crafted application, aka internal bug 23540426.... Read more

    Affected Products : android
    • EPSS Score: %7.72
    • Published: Nov. 03, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-6611

    mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23905951, 23912202, 23953967,... Read more

    Affected Products : android
    • EPSS Score: %0.12
    • Published: Nov. 03, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6610

    libstagefright in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka internal bug 23707088.... Read more

    Affected Products : android
    • EPSS Score: %0.21
    • Published: Nov. 03, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6609

    libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, aka internal bug 22953624.... Read more

    Affected Products : android
    • EPSS Score: %5.92
    • Published: Nov. 03, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6608

    mediaserver in Android 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 19779574, 23680780, 23876444, and 23658... Read more

    Affected Products : android
    • EPSS Score: %3.75
    • Published: Nov. 03, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-8040

    The rtsp_getdlsendtime method in the CNC_Ctrl control in Samsung SmartViewer allows remote attackers to execute arbitrary code via an index value.... Read more

    Affected Products : smartviewer
    • EPSS Score: %0.86
    • Published: Nov. 02, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-8039

    Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vectors to the (1) DVRSetupSave method in the STWAxConfig control or (2) SendCustomPacket method in the STWAxConfigNVR control, which trigger an untrusted pointer derefe... Read more

    Affected Products : smartviewer
    • EPSS Score: %2.77
    • Published: Nov. 02, 2015
    • Modified: Apr. 12, 2025
Showing 20 of 291794 Results