Latest CVE Feed
-
10.0
HIGHCVE-2015-7303
Use-after-free vulnerability in the Update Manager service in Avira Management Console allows remote attackers to execute arbitrary code via a large header.... Read more
Affected Products : management_console- EPSS Score: %9.49
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6938
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this ... Read more
- EPSS Score: %0.86
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-6923
The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x00000ffd ioctl call.... Read more
Affected Products : satellite_express_protocol- EPSS Score: %0.61
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6749
Buffer overflow in the aiff_open function in oggenc/audio.c in vorbis-tools 1.4.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted AIFF file.... Read more
Affected Products : vorbis-tools- EPSS Score: %2.52
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6238
Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3) ga_downloads_... Read more
- EPSS Score: %0.29
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-5603
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors, related to "Velocity Template Injection Vulnerability."... Read more
Affected Products : hipchat- EPSS Score: %83.42
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7296
Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M use a linear algorithm for selecting the ID value in the header of a DNS query performed on behalf of the device itself, which makes... Read more
- EPSS Score: %0.63
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-5993
Buffer overflow in form2ping.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to cause a denial of service (device outage) via a long ipadd... Read more
- EPSS Score: %0.58
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5992
Cross-site scripting (XSS) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to inject arbitrary web script ... Read more
- EPSS Score: %0.50
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5991
Cross-site request forgery (CSRF) vulnerability in form2WlanSetup.cgi on Philippine Long Distance Telephone (PLDT) SpeedSurf 504AN devices with firmware GAN9.8U26-4-TX-R6B018-PH.EN and Kasda KW58293 devices allows remote attackers to hijack the authentica... Read more
- EPSS Score: %0.10
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2917
Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M unintentionally omit the X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via... Read more
- EPSS Score: %0.36
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2916
Cross-site request forgery (CSRF) vulnerability on Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M allows remote attackers to hijack the authentication of arbitrary users.... Read more
- EPSS Score: %0.10
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
7.3
HIGHCVE-2015-2915
Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M have a default password of admin for the admin account, which allows remote attackers to obtain web-management access by leveraging ... Read more
- EPSS Score: %0.20
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2914
Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M use a fixed source-port number in outbound DNS queries performed on behalf of any device, which makes it easier for remote attackers... Read more
- EPSS Score: %0.34
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2864
Retrospect and Retrospect Client before 10.0.2.119 on Windows, before 12.0.2.116 on OS X, and before 10.0.2.104 on Linux improperly generate password hashes, which makes it easier for remote attackers to bypass authentication and obtain access to backup f... Read more
- EPSS Score: %0.61
- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-6548
Multiple SQL injection vulnerabilities in a PHP script in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : web_gateway- EPSS Score: %0.58
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
8.3
HIGHCVE-2015-6547
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands at boot time via unspecified vectors.... Read more
Affected Products : web_gateway- EPSS Score: %3.26
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
7.9
HIGHCVE-2015-5693
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands via vectors related to "traffic capture."... Read more
Affected Products : web_gateway- EPSS Score: %3.12
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
7.9
HIGHCVE-2015-5692
admin_messages.php in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary code by uploading a file with a safe extension and content type, and then... Read more
Affected Products : web_gateway- EPSS Score: %5.79
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5691
Multiple cross-site scripting (XSS) vulnerabilities in PHP scripts in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote attackers to inject arbitrary web script or HTML via unspecified ve... Read more
Affected Products : web_gateway- EPSS Score: %0.52
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025