Latest CVE Feed
-
7.5
HIGHCVE-2015-2117
HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS) before 4.1 patch 3 and 4.2 before patch 1 do not require authentication for JBoss RMI requests, which allows remote attackers to execute arbitrary ... Read more
- EPSS Score: %10.15
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-2116
Unspecified vulnerability in HP Storage Data Protector 7.x before 7.03 build 107 allows remote authenticated users to execute arbitrary code or cause a denial of service via unknown vectors.... Read more
Affected Products : storage_data_protector- EPSS Score: %0.60
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1885
WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.5 Full Profile before 8.5.5.6, when the OAuth grant type requires sending a password, allows remote attack... Read more
Affected Products : websphere_application_server- EPSS Score: %2.14
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
8.5
HIGHCVE-2015-1882
Multiple race conditions in IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 allow remote authenticated users to gain privileges by leveraging thread conflicts that result in Java code execution outside the context of the configur... Read more
Affected Products : websphere_application_server- EPSS Score: %0.95
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-0175
IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenticated users to gain privileges via unspecified vectors.... Read more
Affected Products : websphere_application_server- EPSS Score: %0.49
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-0174
The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : websphere_application_server- EPSS Score: %0.27
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2706
Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete i... Read more
Affected Products : firefox- EPSS Score: %1.13
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1908
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05, as used in Web Content Manager and other products, allo... Read more
Affected Products : websphere_portal- EPSS Score: %0.23
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-1886
The Remote Document Conversion Service (DCS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05 allows remote attackers to cause a denial of service... Read more
Affected Products : websphere_portal- EPSS Score: %2.09
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0176
Cross-site scripting (XSS) vulnerability in MQ XR WebSockets Listener in WMQ Telemetry in IBM WebSphere MQ 8.0 before 8.0.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URI that is included in an error response.... Read more
Affected Products : websphere_mq- EPSS Score: %0.24
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0113
The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 ... Read more
- EPSS Score: %0.22
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-6092
IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which ... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.53
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-6090
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorCommands servlets in IBM Curam Social Program Management (SPM) 5.2 SP6 before EP6, 6.0 SP2 before EP26, 6.0.3 be... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.10
- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3417
Use-after-free vulnerability in the ff_h264_free_tables function in libavcodec/h264.c in FFmpeg before 2.3.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted H.264 data in an MP4 file, as demonstra... Read more
- EPSS Score: %1.02
- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-3416
The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based ... Read more
- EPSS Score: %3.20
- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-3415
The sqlite3VdbeExec function in vdbe.c in SQLite before 3.8.9 does not properly implement comparison operators, which allows context-dependent attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via a ... Read more
- EPSS Score: %3.38
- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-3414
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact ... Read more
- EPSS Score: %3.38
- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3310
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to th... Read more
- EPSS Score: %1.72
- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3148
cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.... Read more
Affected Products : ubuntu_linux fedora debian_linux curl mac_os_x libcurl opensuse system_management_homepage- EPSS Score: %1.44
- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-3145
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a co... Read more
Affected Products : ubuntu_linux fedora debian_linux curl mac_os_x libcurl opensuse solaris system_management_homepage- EPSS Score: %65.10
- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025