Latest CVE Feed
-
4.3
MEDIUMCVE-2015-4236
Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13... Read more
Affected Products : email_security_appliance email_security_appliance_firmware email_security_appliance- EPSS Score: %0.60
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4254
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence Advanced Media Gateway devices with software 1.1(1.40) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90732.... Read more
Affected Products : telepresence_advanced_media_gateway- EPSS Score: %0.12
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3650
vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer... Read more
- EPSS Score: %0.13
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2963
The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonst... Read more
Affected Products : paperclip- EPSS Score: %0.48
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4259
The Integrated Management Controller on Cisco Unified Computing System (UCS) C servers with software 1.5(3) and 1.6(0.16) has a default SSL certificate, which makes it easier for man-in-the-middle attackers to bypass cryptographic protection mechanisms by... Read more
- EPSS Score: %0.14
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2015-2970
index.php in LEMON-S PHP Simple Oekaki BBS before 1.21 allows remote attackers to delete arbitrary files via the oekakis parameter.... Read more
Affected Products : simple_oekaki- EPSS Score: %1.97
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2969
Cross-site scripting (XSS) vulnerability in index.php in LEMON-S PHP Simple Oekaki BBS before 1.21 allows remote attackers to inject arbitrary web script or HTML via the oekakis parameter.... Read more
Affected Products : simple_oekaki_bbs- EPSS Score: %0.32
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2967
Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : cacti- EPSS Score: %0.32
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4260
Cross-site scripting (XSS) vulnerability in Cisco Hosted Collaboration Solution 10.6(1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu14862.... Read more
Affected Products : hosted_collaboration_solution- EPSS Score: %0.26
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-4244
The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.... Read more
Affected Products : asr_5000_series_software- EPSS Score: %0.18
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4258
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MSE 8000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90444.... Read more
Affected Products : telepresence_mse_8000_series- EPSS Score: %0.11
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4257
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MCU 4500 devices with software 4.5(1.55) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90710.... Read more
Affected Products : telepresence_mcu_software- EPSS Score: %0.11
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4256
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP VCR devices with software 3.0(1.27) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90736.... Read more
Affected Products : telepresence_ip_vcr_3.0- EPSS Score: %0.11
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4255
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP Gateway devices with software 2.0(3.34) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90734.... Read more
Affected Products : telepresence_ip_gateway- EPSS Score: %0.11
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4253
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence Serial Gateway devices with software 1.0(1.42) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90728.... Read more
Affected Products : telepresence_serial_gateway- EPSS Score: %0.11
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-4252
Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence ISDN Gateway devices with software 2.2(1.106) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90724.... Read more
Affected Products : telepresence_isdn_gw_3241- EPSS Score: %0.11
- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-1793
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spo... Read more
- EPSS Score: %82.68
- Published: Jul. 09, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-5118
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler bef... Read more
- EPSS Score: %68.03
- Published: Jul. 09, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-5117
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler b... Read more
- EPSS Score: %13.60
- Published: Jul. 09, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-5116
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow remote at... Read more
- EPSS Score: %27.66
- Published: Jul. 09, 2015
- Modified: Apr. 12, 2025