Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.8

    MEDIUM
    CVE-2015-6309

    Cisco Email Security Appliance (ESA) 8.5.6-106 and 9.6.0-042 allows remote authenticated users to cause a denial of service (file-descriptor consumption and device reload) via crafted HTTP requests, aka Bug ID CSCuw32211.... Read more

    • EPSS Score: %0.31
    • Published: Oct. 02, 2015
    • Modified: Apr. 12, 2025
  • 4.0

    MEDIUM
    CVE-2015-6308

    Cisco NX-OS 6.0(2)U6(0.46) on N3K devices allows remote authenticated users to cause a denial of service (temporary SNMP outage) via an SNMP request for an OID that does not exist, aka Bug ID CSCuw36684.... Read more

    Affected Products : nx-os nx-os
    • EPSS Score: %0.39
    • Published: Oct. 02, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-5653

    Buffer overflow in Canary Labs Trend Web Server before 9.5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet.... Read more

    Affected Products : trendweb
    • EPSS Score: %1.34
    • Published: Oct. 02, 2015
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2015-6602

    libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demonstrated by an attack against use of libutils by libstagefright in Android 5.x.... Read more

    Affected Products : android
    • EPSS Score: %1.77
    • Published: Oct. 02, 2015
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2015-4546

    Directory traversal vulnerability in EMC RSA OneStep 6.9 before build 559, as used in RSA Certificate Manager and RSA Registration Manager through 6.9 build 558 and other products, allows remote attackers to read arbitrary files via a crafted KCSOSC_ERROR... Read more

    Affected Products : rsa_certificate_manager rsa_onestep
    • EPSS Score: %3.40
    • Published: Oct. 02, 2015
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2015-3876

    libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file.... Read more

    Affected Products : android
    • EPSS Score: %4.56
    • Published: Oct. 02, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-2858

    Datalex airline booking software before 2015-09-03 allows remote attackers to read or write to arbitrary user data via a modified profileId parameter to (1) ValidateFormAction.do or (2) ProfileConfirmEditAddressAction.do.... Read more

    Affected Products : airline_booking_software
    • EPSS Score: %0.27
    • Published: Oct. 02, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-7612

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations page in Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.9 and earlier allow remote attackers to hijack the authentication of administrators for requests that have... Read more

    Affected Products : vulnerability_manager
    • EPSS Score: %0.12
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 3.6

    LOW
    CVE-2015-7311

    libxl in Xen 4.1.x through 4.6.x does not properly handle the readonly flag on disks when using the qemu-xen device model, which allows local guest users to write to a read-only disk image.... Read more

    Affected Products : xen
    • EPSS Score: %0.07
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-7236

    Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code.... Read more

    • EPSS Score: %8.21
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2015-1338

    kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.... Read more

    Affected Products : ubuntu_linux apport
    • EPSS Score: %0.38
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2015-1335

    lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.... Read more

    Affected Products : ubuntu_linux lxc
    • EPSS Score: %0.08
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6575

    SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly consider integer promotion, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via crafted atoms ... Read more

    Affected Products : android
    • EPSS Score: %18.58
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-3864

    Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted MPEG-4 data, aka internal bug 23034759. NOTE:... Read more

    Affected Products : android
    • EPSS Score: %84.44
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2015-3863

    Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary code and read arbitrary Keystore keys via an application that uses a crafted blob in an insert operation,... Read more

    Affected Products : android
    • EPSS Score: %0.21
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-3861

    Multiple integer overflows in the addVorbisCodecInfo function in matroska/MatroskaExtractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M allow remote attackers to cause a denial of service (device inoperability) via crafted Matroska... Read more

    Affected Products : android
    • EPSS Score: %0.31
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2015-3860

    packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters in the passwordEntry input field, which allows physically proximate attackers to bypass intended access res... Read more

    Affected Products : android
    • EPSS Score: %0.04
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2015-3858

    The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypass an intended user-confirmation requirement for SMS shor... Read more

    Affected Products : android
    • EPSS Score: %0.16
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2015-3849

    The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android before 5.1.1 LMY48M does not check the return values of certain read operations, which allows attackers to execute arbitrary code via an application that sen... Read more

    Affected Products : android
    • EPSS Score: %0.52
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-3845

    The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identification of binder objects in an append operation, which allows attackers to obtain a different application... Read more

    Affected Products : android
    • EPSS Score: %0.11
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
Showing 20 of 291659 Results