Latest CVE Feed
-
7.8
HIGHCVE-2015-7602
Directory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in a RETR command.... Read more
Affected Products : bisonftp- EPSS Score: %52.58
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-7601
Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a RETR command.... Read more
Affected Products : pcman\'s_ftp_server- EPSS Score: %52.58
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-7337
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.... Read more
- EPSS Score: %0.78
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7320
Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified v... Read more
Affected Products : appointment_booking_calendar- EPSS Score: %0.22
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-7319
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating t... Read more
Affected Products : appointment_booking_calendar- EPSS Score: %0.42
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5076
Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) version parameter in protected/views/admin/formEditor.php; the (2) importId parameter in protected... Read more
Affected Products : x2crm- EPSS Score: %0.30
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5075
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators for requests that create an administrative account via a crafted request to index.php/users/create.... Read more
Affected Products : x2crm- EPSS Score: %0.97
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-5074
Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.9 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a .pht extensio... Read more
Affected Products : x2crm- EPSS Score: %12.90
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-0299
Multiple cross-site scripting (XSS) vulnerabilities in Open Source Point of Sale 2.3.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : open_source_point_of_sale- EPSS Score: %0.16
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-5711
TIBCO Managed File Transfer Internet Server before 7.2.5, Managed File Transfer Command Center before 7.2.5, Slingshot before 1.9.4, and Vault before 2.0.1 allow remote authenticated users to obtain sensitive information via a crafted HTTP request.... Read more
Affected Products : managed_file_transfer_command_center managed_file_transfer_internet_server slingshot vault- EPSS Score: %0.07
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2015-5442
Unspecified vulnerability in HP Software Update before 5.005.002.002 allows local users to gain privileges via unknown vectors.... Read more
Affected Products : software_update- EPSS Score: %0.09
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0852
Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.... Read more
Affected Products : freeimage- EPSS Score: %2.31
- Published: Sep. 29, 2015
- Modified: Apr. 12, 2025
-
3.6
LOWCVE-2015-6927
vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs container (CT) root users to change the root password for arbitrary ploop containe... Read more
Affected Products : vzctl- EPSS Score: %0.08
- Published: Sep. 28, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6806
The MScrollV function in ansi.c in GNU screen 4.3.1 and earlier does not properly limit recursion, which allows remote attackers to cause a denial of service (stack consumption) via an escape sequence with a large repeat count value.... Read more
- EPSS Score: %0.64
- Published: Sep. 28, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-5957
Buffer overflow in the DumpSysVar function in var.c in Remind before 3.1.15 allows attackers to have unspecified impact via a long name.... Read more
- EPSS Score: %0.49
- Published: Sep. 28, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5400
Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.... Read more
- EPSS Score: %26.16
- Published: Sep. 28, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5185
The lookupProviders function in providerMgr.c in sblim-sfcb 1.3.4 and 1.3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty className in a packet.... Read more
- EPSS Score: %1.18
- Published: Sep. 28, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1781
Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, ... Read more
- EPSS Score: %5.08
- Published: Sep. 28, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-5703
SQL injection vulnerability in the public key discovery API call in Open-Xchange OX Guard before 2.0.0-rev8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : open-xchange_ox_guard- EPSS Score: %0.35
- Published: Sep. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5375
Cross-site scripting (XSS) vulnerability in unspecified dialogs for printing content in the Front End in Open-Xchange Server 6 and OX App Suite before 6.22.8-rev8, 6.22.9 before 6.22.9-rev15m, 7.x before 7.6.1-rev25, and 7.6.2 before 7.6.2-rev20 allows re... Read more
- EPSS Score: %0.36
- Published: Sep. 28, 2015
- Modified: Apr. 12, 2025