Latest CVE Feed
-
7.2
HIGHCVE-2015-5198
libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privileges via unspecified vectors, related to the VDPAU_DRIVER_PATH environment variable.... Read more
- EPSS Score: %0.05
- Published: Sep. 08, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-3247
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspeci... Read more
- EPSS Score: %0.77
- Published: Sep. 08, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3241
OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) ... Read more
Affected Products : nova- EPSS Score: %3.78
- Published: Sep. 08, 2015
- Modified: Apr. 12, 2025
-
3.7
LOWCVE-2015-1841
The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.... Read more
Affected Products : enterprise_virtualization- EPSS Score: %0.05
- Published: Sep. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5625
Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter.... Read more
Affected Products : opendocman- EPSS Score: %0.35
- Published: Sep. 07, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5624
Buffer overflow in the ExecCall method in c2lv6.ocx in the FreeBit ELPhoneBtnV6 ActiveX control allows remote attackers to execute arbitrary code via a crafted HTML document, related to the discontinued "Click to Live" service.... Read more
Affected Products : elphonebtnv6_activex_control- EPSS Score: %2.50
- Published: Sep. 07, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2989
Cross-site scripting (XSS) vulnerability in index.php in LEMON-S PHP Twit BBS allows remote attackers to inject arbitrary web script or HTML via the imagetitle parameter.... Read more
Affected Products : twit_bbs- EPSS Score: %0.25
- Published: Sep. 07, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6826
The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other ... Read more
- EPSS Score: %0.89
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6825
The ff_frame_thread_init function in libavcodec/pthread_frame.c in FFmpeg before 2.7.2 mishandles certain memory-allocation failures, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other im... Read more
Affected Products : ffmpeg- EPSS Score: %0.71
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6824
The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does not initialize certain pixbuf data structures, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impact vi... Read more
- EPSS Score: %0.89
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6823
The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does not initialize certain context data, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impact via crafted A... Read more
Affected Products : ffmpeg- EPSS Score: %0.71
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6822
The destroy_buffers function in libavcodec/sanm.c in FFmpeg before 2.7.2 does not properly maintain height and width values in the video context, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or ... Read more
Affected Products : ffmpeg- EPSS Score: %0.89
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6821
The ff_mpv_common_init function in libavcodec/mpegvideo.c in FFmpeg before 2.7.2 does not properly maintain the encoding context, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact... Read more
Affected Products : ffmpeg- EPSS Score: %0.71
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6820
The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax element before proceeding with Spectral Band Replication calculations, which allows remote attackers to cause a denial of service (out-o... Read more
- EPSS Score: %0.89
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6819
Multiple integer underflows in the ff_mjpeg_decode_frame function in libavcodec/mjpegdec.c in FFmpeg before 2.7.2 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted MJPEG ... Read more
Affected Products : ffmpeg- EPSS Score: %0.52
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6818
The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (aka image header) chunk in a PNG image, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possib... Read more
- EPSS Score: %0.89
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2986
Cross-site scripting (XSS) vulnerability in rakuto.net hitSuji (rktSNS2) 0.2.2b allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : rktsns2- EPSS Score: %0.25
- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2985
Cross-site scripting (XSS) vulnerability in guide-park.com BBS X102 1.03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : bbs_x102- EPSS Score: %0.25
- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6276
Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insufficient access control, which allows remote attackers to obtain cleartext versions of HTTPS traffic or spoof devices via a direct reques... Read more
- EPSS Score: %0.17
- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-5986
openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.... Read more
- EPSS Score: %47.84
- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025