Latest CVE Feed
-
6.8
MEDIUMCVE-2015-5792
WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs... Read more
- EPSS Score: %1.54
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5791
WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than... Read more
- EPSS Score: %1.54
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5790
WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs... Read more
- EPSS Score: %1.54
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-5789
WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs... Read more
- EPSS Score: %1.54
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5788
The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain sensitive image information via vectors involving a CANVAS element.... Read more
- EPSS Score: %0.47
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5767
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5765.... Read more
- EPSS Score: %0.65
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5765
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5767.... Read more
- EPSS Score: %0.65
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5764
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5765 and CVE-2015-5767.... Read more
- EPSS Score: %0.85
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3801
The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intended single-cookie restriction via unspecified vectors.... Read more
- EPSS Score: %0.98
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-8611
The __sflush function in fflush.c in stdio in libc in FreeBSD 10.1 and the kernel in Apple iOS before 9 mishandles failures of the write system call, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-bas... Read more
- EPSS Score: %0.11
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-7235
Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a dex_reservations_calendar_load2 action o... Read more
Affected Products : cp_reservation_calender- EPSS Score: %2.60
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-7234
The OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology and OSF Import modules are enabled, allows user-assisted remote attackers to delete arbitrary files via unspecified vectors.... Read more
Affected Products : open_semantic_framework- EPSS Score: %0.70
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
5.1
MEDIUMCVE-2015-7233
Cross-site request forgery (CSRF) vulnerability in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Import module is enabled, allows remote attackers to hijack the authentication of administrators for requests that create new OSF datasets vi... Read more
Affected Products : open_semantic_framework- EPSS Score: %0.12
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-7232
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology module is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vecto... Read more
Affected Products : open_semantic_framework- EPSS Score: %0.26
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-7231
The Commerce Commonwealth (CBA) module 7.x-1.x before 7.x-1.5 for Drupal does not properly validate payments, which allows remote attackers to make a failed payment appear valid via a crafted URL, related to a "response from commweb."... Read more
Affected Products : commerce_commonwealth- EPSS Score: %0.22
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-7230
The Workbench Email module 7.x-3.x before 7.x-3.4 for Drupal allows remote authenticated users with certain permissions to bypass node and field validation by saving a node.... Read more
Affected Products : workbench_email- EPSS Score: %0.14
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-7229
The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post t... Read more
Affected Products : twitter- EPSS Score: %0.16
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-7228
The RESTful module 7.x-1.x before 7.x-1.3 for Drupal does not properly cache pages of authenticated users when using non-cookie authentication providers, which allows remote attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : restful- EPSS Score: %0.27
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-7227
The Fieldable Panels Panes module 7.x-1.x before 7.x-1.7 for Drupal does not properly check permissions to edit Fieldable Panels Panes entities, which allows remote authenticated users to edit panes by leveraging permissions to edit panels.... Read more
Affected Products : fieldable_panels_panes- EPSS Score: %0.13
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-7226
The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the display property, which allows remote attackers to obtain sensitive information via vectors related to the ac... Read more
Affected Products : administration_views- EPSS Score: %0.29
- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025