Latest CVE Feed
-
6.5
MEDIUMCVE-2015-5673
eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper popen calls, which allows remote attackers to execute arbitrary commands via an HTTP request that includes shell metacharacters in an ar... Read more
Affected Products : isucon_5_qualifier_eventapp- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-5021
IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors.... Read more
Affected Products : infosphere_information_server- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-4927
The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses world-writable permissions for unspecified files, which allows local users to gain privileges by writing ... Read more
Affected Products : tivoli_storage_manager- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-2903
The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password.... Read more
Affected Products : arcsight_smartconnectors- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2902
HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate.... Read more
Affected Products : arcsight_smartconnectors- Published: Nov. 04, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-8074
mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23540907 and 23515142, a different vulnerability than C... Read more
Affected Products : android- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-8073
mediaserver in Android 4.4 and 5.1 before 5.1.1 LMY48X allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 14388161, a different vulnerability than CVE-2015-6608 and... Read more
Affected Products : android- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-8072
mediaserver in Android 4.4 through 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23881715, a different vulner... Read more
Affected Products : android- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-6614
Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently bypass intended network-interface restrictions, perform expensive data transfers, or cause a denial of service (call-reception outage or mute manipulation),... Read more
Affected Products : android- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
5.1
MEDIUMCVE-2015-6613
Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port, and consequently gain privileges, via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka ... Read more
Affected Products : android- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-6612
libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges via a crafted application, aka internal bug 23540426.... Read more
Affected Products : android- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6611
mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23905951, 23912202, 23953967,... Read more
Affected Products : android- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-6610
libstagefright in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka internal bug 23707088.... Read more
Affected Products : android- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-6609
libutils in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted audio file, aka internal bug 22953624.... Read more
Affected Products : android- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-6608
mediaserver in Android 5.x before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 19779574, 23680780, 23876444, and 23658... Read more
Affected Products : android- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-8040
The rtsp_getdlsendtime method in the CNC_Ctrl control in Samsung SmartViewer allows remote attackers to execute arbitrary code via an index value.... Read more
Affected Products : smartviewer- Published: Nov. 02, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-8039
Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vectors to the (1) DVRSetupSave method in the STWAxConfig control or (2) SendCustomPacket method in the STWAxConfigNVR control, which trigger an untrusted pointer derefe... Read more
Affected Products : smartviewer- Published: Nov. 02, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8038
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) sharedjobmanager or (2) SOMServiceObjDialog.... Read more
Affected Products : fortimanager_firmware- Published: Nov. 02, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8037
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SOMVpnSSLPortalDialog or (2) FGDMngUpdHistory.... Read more
Affected Products : fortimanager_firmware- Published: Nov. 02, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-8036
Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the session... Read more
- Published: Nov. 02, 2015
- Modified: Apr. 12, 2025