Latest CVE Feed
-
4.0
MEDIUMCVE-2015-3289
OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them.... Read more
Affected Products : glance- EPSS Score: %0.36
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
6.0
MEDIUMCVE-2015-3235
Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.... Read more
Affected Products : foreman- EPSS Score: %0.65
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3155
Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.... Read more
Affected Products : foreman- EPSS Score: %0.56
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-1844
Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.... Read more
Affected Products : foreman- EPSS Score: %0.38
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-1819
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.... Read more
Affected Products : ubuntu_linux enterprise_linux fedora debian_linux mac_os_x linux opensuse solaris iphone_os tvos +3 more products- EPSS Score: %2.46
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-1816
Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.... Read more
Affected Products : foreman- EPSS Score: %0.18
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8155
GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.... Read more
Affected Products : gnutls- EPSS Score: %0.29
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3576
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.... Read more
- EPSS Score: %8.68
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2452
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2441.... Read more
Affected Products : internet_explorer- EPSS Score: %22.82
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2451
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2450.... Read more
Affected Products : internet_explorer- EPSS Score: %22.82
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2450
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2451.... Read more
Affected Products : internet_explorer- EPSS Score: %22.82
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2449
Microsoft Internet Explorer 7 through 11 and Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "ASLR Bypass."... Read more
- EPSS Score: %19.04
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2448
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."... Read more
Affected Products : internet_explorer- EPSS Score: %22.82
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2447
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2446.... Read more
Affected Products : internet_explorer- EPSS Score: %28.83
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2446
Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2447.... Read more
- EPSS Score: %22.82
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2445
Microsoft Internet Explorer 10 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "ASLR Bypass."... Read more
Affected Products : internet_explorer- EPSS Score: %17.18
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2444
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2442.... Read more
Affected Products : internet_explorer- EPSS Score: %25.58
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2443
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."... Read more
Affected Products : internet_explorer- EPSS Score: %16.31
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2442
Microsoft Internet Explorer 8 through 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2444... Read more
- EPSS Score: %22.82
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2441
Microsoft Internet Explorer 7 through 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2452... Read more
- EPSS Score: %22.82
- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025