Latest CVE Feed
-
5.8
MEDIUMCVE-2015-6548
Multiple SQL injection vulnerabilities in a PHP script in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : web_gateway- EPSS Score: %0.58
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
8.3
HIGHCVE-2015-6547
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands at boot time via unspecified vectors.... Read more
Affected Products : web_gateway- EPSS Score: %3.26
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
7.9
HIGHCVE-2015-5693
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands via vectors related to "traffic capture."... Read more
Affected Products : web_gateway- EPSS Score: %3.12
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
7.9
HIGHCVE-2015-5692
admin_messages.php in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary code by uploading a file with a safe extension and content type, and then... Read more
Affected Products : web_gateway- EPSS Score: %5.79
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5691
Multiple cross-site scripting (XSS) vulnerabilities in PHP scripts in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote attackers to inject arbitrary web script or HTML via unspecified ve... Read more
Affected Products : web_gateway- EPSS Score: %0.52
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
8.5
HIGHCVE-2015-5690
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging a "redirect."... Read more
Affected Products : web_gateway- EPSS Score: %1.55
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5689
ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Solutions Suite (GSS) before 3.0 HF2 12.0.0.8010 and Symantec Deployment Solution (DS) before 7.6 HF4 12.0.0.7045 performs improper sign-extend operations before array-element accesses, which allows... Read more
- EPSS Score: %3.00
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2014-9229
Multiple SQL injection vulnerabilities in interface PHP scripts in the Manager component in Symantec Endpoint Protection (SEP) before 12.1.6 allow remote authenticated users to execute arbitrary SQL commands by leveraging the Limited Administrator role.... Read more
Affected Products : endpoint_protection- EPSS Score: %0.44
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2014-9228
sysplant.sys in the Manager component in Symantec Endpoint Protection (SEP) before 12.1.6 allows local users to cause a denial of service (blocked system shutdown) by triggering an unspecified deadlock condition.... Read more
Affected Products : endpoint_protection- EPSS Score: %0.06
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
4.4
MEDIUMCVE-2014-9227
Multiple untrusted search path vulnerabilities in the Manager component in Symantec Endpoint Protection (SEP) before 12.1.6 allow local users to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : endpoint_protection- EPSS Score: %0.08
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5637
The Newphoria Photon application before 1.2 for Android allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.... Read more
Affected Products : 1.1- EPSS Score: %0.40
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5636
The Newphoria Reversi application before 1.0.3 for Android and before 1.2 for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.... Read more
Affected Products : reversi- EPSS Score: %0.40
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5635
The Newphoria Koritore application before 1.1 for Android and before 1.1 for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.... Read more
Affected Products : koritore- EPSS Score: %0.40
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5634
The Newphoria MEGAPHONE MUSIC application before 1.1 for Android and before 1.1 for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.... Read more
Affected Products : megaphone_music- EPSS Score: %0.40
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5633
The Newphoria Auction Camera application for iOS and before 1.2 for Android allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.... Read more
Affected Products : auction_camera- EPSS Score: %0.40
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5632
The runtime engine in the Newphoria applican framework before 1.12.3 for Android and before 1.12.2 for iOS allows attackers to bypass a whitelist.xml URL whitelist protection mechanism and obtain API access via unspecified vectors.... Read more
Affected Products : applican- EPSS Score: %0.40
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6301
The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun72171.... Read more
- EPSS Score: %0.57
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-6300
Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) via crafted (1) CLI or (2) GUI commands, aka Bug ID CSCuw24694.... Read more
- EPSS Score: %0.39
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-6299
SQL injection vulnerability in the web interface in Cisco Unity Connection 9.1(1.2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted POST request, aka Bug ID CSCuv63824.... Read more
Affected Products : unity_connection- EPSS Score: %0.29
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
4.8
MEDIUMCVE-2015-6295
Cisco NX-OS 6.1(2)I3(4) and 7.0(3)I1(1) on Nexus 9000 (N9K) devices allows remote attackers to cause a denial of service (CPU consumption or control-plane instability) or trigger unintended traffic forwarding via a Layer 2 packet with a reserved VLAN numb... Read more
Affected Products : nx-os nx-os nexus_9000 nexus_93120tx nexus_93128tx nexus_9332pq nexus_9336pq_aci_spine nexus_9372px nexus_9372tx- EPSS Score: %0.65
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025