Latest CVE Feed
-
3.2
LOWCVE-2015-5011
IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, ... Read more
- EPSS Score: %0.12
- Published: Oct. 26, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-4981
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain sensitive information from system memory via unspecified vectors.... Read more
- EPSS Score: %0.06
- Published: Oct. 26, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-4974
IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors.... Read more
- EPSS Score: %0.10
- Published: Oct. 26, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6484
3S-Smart CODESYS Gateway Server before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted (1) GET or (2) POST request.... Read more
Affected Products : codesys_gateway_server- EPSS Score: %0.31
- Published: Oct. 25, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6341
The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a denial of service (client disconnection) via unspecified vectors, aka Bug ID CSCuw10610.... Read more
- EPSS Score: %0.44
- Published: Oct. 25, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-6335
The policy implementation in Cisco FireSIGHT Management Center 5.3.1.7, 5.4.0.4, and 6.0.0 for VMware allows remote authenticated administrators to bypass intended policy restrictions and execute Linux commands as root via unspecified vectors, aka Bug ID ... Read more
Affected Products : firesight_system_software- EPSS Score: %0.34
- Published: Oct. 25, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6327
The IKEv1 implementation in Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.8), 9.2 before 9.2(4), and 9.3 before 9.3(3) ... Read more
- EPSS Score: %0.41
- Published: Oct. 25, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6326
Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.6), 9.2 before 9.2(4), 9.3 before 9.3(3.5), and 9.4 before 9.4(1.5) allow... Read more
- EPSS Score: %0.43
- Published: Oct. 25, 2015
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-6325
Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 before 9.0(4.37), 9.1 before 9.1(6.4), 9.2 before 9.2(4), 9.3 before 9.3(3.1), and 9.4 before 9.4(1.1) allow... Read more
- EPSS Score: %0.68
- Published: Oct. 25, 2015
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-6324
The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) software 9.0 before 9.0(4.37), 9.1 before 9.1(6.6), 9.2 before 9.2(4), 9.3 before 9.3(3.5), and 9.4 before 9.4(2) allows remote attackers to cause a denial of service (device reloa... Read more
- EPSS Score: %0.28
- Published: Oct. 25, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-1005
IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : scada_web_server- EPSS Score: %0.06
- Published: Oct. 25, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-1003
Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname.... Read more
Affected Products : scada_web_server- EPSS Score: %0.54
- Published: Oct. 25, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2015-1002
IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string.... Read more
Affected Products : scada_web_server- EPSS Score: %0.50
- Published: Oct. 25, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-1001
Multiple stack-based buffer overflows in IniNet embeddedWebServer (aka eWebServer) before 2.02 allow remote attackers to execute arbitrary code via a long field in an HTTP request.... Read more
Affected Products : scada_web_server- EPSS Score: %1.35
- Published: Oct. 25, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-7023
CFNetwork in Apple iOS before 9.1 and OS X before 10.11.1 does not properly consider the uppercase-versus-lowercase distinction during cookie parsing, which allows remote web servers to overwrite cookies via unspecified vectors.... Read more
- EPSS Score: %0.74
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-7021
The Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to gain privileges or cause a denial of service (kernel memory corruption) via unspecified vectors.... Read more
- EPSS Score: %0.04
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025
-
5.6
MEDIUMCVE-2015-7020
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via unspecified vectors, a different ... Read more
- EPSS Score: %0.04
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025
-
5.6
MEDIUMCVE-2015-7019
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via unspecified vectors, a different ... Read more
- EPSS Score: %0.04
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-7018
FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-69... Read more
- EPSS Score: %1.87
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2015-7016
The MCX Application Restrictions component in Apple OS X before 10.11.1, when Managed Configuration is enabled, mishandles provisioning profiles, which allows attackers to bypass intended entitlement restrictions and gain privileges via a crafted develope... Read more
- EPSS Score: %0.33
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025