Latest CVE Feed
-
9.3
HIGHCVE-2015-2372
vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Me... Read more
- EPSS Score: %16.31
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-2369
Untrusted search path vulnerability in Windows Media Device Manager in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a Trojan horse DLL in the current ... Read more
- EPSS Score: %8.17
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-2368
Untrusted search path vulnerability in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Windows... Read more
- EPSS Score: %9.39
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-2362
Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly initialize guest OS system data structures, which allows guest OS users to execute arbitrary code on the host OS by leve... Read more
- EPSS Score: %0.70
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-2361
Hyper-V in Microsoft Windows 8.1 and Windows Server 2012 R2 does not properly initialize guest OS system data structures, which allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (buffer overflow) by leveraging gue... Read more
- EPSS Score: %0.55
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1767
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE... Read more
Affected Products : internet_explorer- EPSS Score: %18.14
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1738
Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015... Read more
Affected Products : internet_explorer- EPSS Score: %28.14
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1733
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-20... Read more
Affected Products : internet_explorer- EPSS Score: %28.14
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1729
Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."... Read more
Affected Products : internet_explorer- EPSS Score: %24.55
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-5362
The BFD daemon in Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R8, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.1X50 before 14.1X50-D85,... Read more
- EPSS Score: %3.12
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-5359
Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D10, 13.2 before 13.2R7, 13.3 before 13.3R5, 14.1R3 before 14.1R3-S2, 14.1 before 14.1R4, 14.2 before 14.2R2, a... Read more
- EPSS Score: %0.46
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-5358
Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R7, 13.2X51 before 13.2X51-D35, 13.2X52 before 13.2X52-D25, 13.3 before 13.3R6, 14.1R3 bef... Read more
- EPSS Score: %1.89
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-5145
validators.URLValidator in Django 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.... Read more
Affected Products : django- EPSS Score: %1.94
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5144
Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 uses an incorrect regular expression, which allows remote attackers to inject arbitrary headers and conduct HTTP response splitting attacks via a newline character in an... Read more
- EPSS Score: %1.49
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-5143
The session backends in Django before 1.4.21, 1.5.x through 1.6.x, 1.7.x before 1.7.9, and 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (session store consumption) via multiple requests with unique session keys.... Read more
- EPSS Score: %15.81
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4270
Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSIGHT System Software 5.3.1.5 and 6.0.0 allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuv22557, CSCuv22583, CSCuv22632, CSCuv22641, CSCuv2265... Read more
Affected Products : firesight_system_software- EPSS Score: %0.26
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4268
Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1.2(1.198) and 1.3(0.876) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST r... Read more
Affected Products : identity_services_engine_software- EPSS Score: %0.26
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3007
The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set system ports console insecure" feature, which allows physically proximate atta... Read more
- EPSS Score: %0.04
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
4.4
MEDIUMCVE-2015-1946
IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.6, and WebSphere Virtual Enterprise 7.0 before 7.0.0.6 for WebSphere Application Server (WAS) 7.0 and 8.0, does not properly implement user roles, which allows local users to gain privileges via unsp... Read more
- EPSS Score: %0.06
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
6.0
MEDIUMCVE-2015-1936
The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticated users to hijack sessions via the JSESSIONID parameter.... Read more
Affected Products : websphere_application_server- EPSS Score: %0.31
- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025