Latest CVE Feed
-
4.0
MEDIUMCVE-2015-6587
The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.... Read more
- EPSS Score: %0.62
- Published: Sep. 02, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6737
Cross-site scripting (XSS) vulnerability in the Widgets extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors involving base64 encoded content.... Read more
Affected Products : widgets- EPSS Score: %0.41
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6736
The Quiz extension for MediaWiki allows remote attackers to cause a denial of service via regex metacharacters in a regular expression.... Read more
Affected Products : quiz- EPSS Score: %1.61
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6735
The reset functionality in the TimedMediaHandler extension for MediaWiki does not create a new transcode, which allows remote attackers to cause a denial of service (transcode deletion) by resetting a transcode.... Read more
Affected Products : timedmediahandler- EPSS Score: %1.61
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6734
Cross-site scripting (XSS) vulnerability in contrib/cssgen.php in the GeSHi, as used in the SyntaxHighlight_GeSHi extension and MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2, allows remote attackers to inject arbitrary web scrip... Read more
Affected Products : mediawiki- EPSS Score: %0.41
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6733
GeSHi, as used in the SyntaxHighlight_GeSHi extension and MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2, allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors.... Read more
Affected Products : mediawiki- EPSS Score: %1.61
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6732
Multiple cross-site scripting (XSS) vulnerabilities in the SemanticForms extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via the (1) wpSummary parameter to Special:FormEdit, the (2) "Template label (optional)" field i... Read more
Affected Products : semanticforms- EPSS Score: %0.65
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6731
Multiple cross-site scripting (XSS) vulnerabilities in the SemanticForms extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via a (1) section_*, (2) template_*, (3) label_*, or (4) new_template parameter to Special:Creat... Read more
Affected Products : semanticforms- EPSS Score: %0.48
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6730
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to inject arbitrary web script or HTML via the f parameter, which is not properly handled in an error... Read more
Affected Products : mediawiki- EPSS Score: %0.41
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6729
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to inject arbitrary web script or HTML via the rel404 parameter, which is not properly handled in an ... Read more
Affected Products : mediawiki- EPSS Score: %0.41
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6728
The ApiBase::getWatchlistUser function in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 does not perform token comparison in constant time, which allows remote attackers to guess the watchlist token and bypass CSRF protection vi... Read more
Affected Products : mediawiki- EPSS Score: %0.20
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6727
The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.... Read more
- EPSS Score: %0.60
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6520
IPPUSBXD before 1.22 listens on all interfaces, which allows remote attackers to obtain access to USB connected printers via a direct request.... Read more
Affected Products : ippusbxd- EPSS Score: %0.82
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2807
Cross-site scripting (XSS) vulnerability in js/window.php in the Navis DocumentCloud plugin before 0.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.... Read more
Affected Products : navis_documentcloud- EPSS Score: %6.89
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2013-7444
The Special:Contributions page in MediaWiki before 1.22.0 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.... Read more
Affected Products : mediawiki- EPSS Score: %0.60
- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-6526
The perf_callchain_user_64 function in arch/powerpc/perf/callchain.c in the Linux kernel before 4.0.2 on ppc64 platforms allows local users to cause a denial of service (infinite loop) via a deep 64-bit userspace backtrace.... Read more
Affected Products : linux_kernel- EPSS Score: %0.04
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6272
Cisco IOS XE 2.1.0 through 2.2.3 and 2.3.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted H.323 packet, aka Bug ID CSCsx35393, CSCsx07... Read more
Affected Products : ios_xe ios_xe asr_1001 asr_1002 asr_1002-x asr_1004 asr_1006 asr_1013 asr_1001-x- EPSS Score: %0.43
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6271
Cisco IOS XE 2.1.0 through 2.4.3 and 2.5.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted SIP packet, aka Bug IDs CSCta74749 and CSCta... Read more
Affected Products : ios_xe ios_xe asr_1001 asr_1002 asr_1002-x asr_1004 asr_1006 asr_1013 asr_1001-x- EPSS Score: %0.43
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6270
Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted IPv6 packet, aka Bug ID CSCsv98555.... Read more
Affected Products : ios_xe ios_xe asr_1001 asr_1002 asr_1002-x asr_1004 asr_1006 asr_1013 asr_1001-x- EPSS Score: %0.43
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6269
Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted (1) IPv4 or (2) IPv6 packet, aka Bug ID CSCsw69990.... Read more
Affected Products : ios_xe ios_xe asr_1001 asr_1002 asr_1002-x asr_1004 asr_1006 asr_1013 asr_1001-x- EPSS Score: %0.43
- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025