Latest CVE Feed
-
5.8
MEDIUMCVE-2015-0557
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.... Read more
- EPSS Score: %2.10
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-0556
Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.... Read more
- EPSS Score: %2.09
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-0251
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.... Read more
- EPSS Score: %0.77
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0248
The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evaluated ... Read more
Affected Products : enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_eus opensuse solaris xcode subversion enterprise_linux_hpc_node prosafe-rs_firmware +1 more products- EPSS Score: %11.43
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-0202
The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.... Read more
- EPSS Score: %1.99
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2823
Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Profession... Read more
- EPSS Score: %0.50
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2822
Siemens SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2 and SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2 allow man-in-the-middle attackers to cause a denial of service via crafted packets on TCP port 102.... Read more
Affected Products : wincc- EPSS Score: %0.60
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1799
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 3.x and 4.x before 4.2.8p2 performs state-variable updates upon receiving certain invalid packets, which makes it easier for man-in-the-middle attackers to cause a denial of s... Read more
Affected Products : ntp- EPSS Score: %0.68
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
1.8
LOWCVE-2015-1798
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MA... Read more
Affected Products : ntp- EPSS Score: %0.68
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2015-1473
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cau... Read more
- EPSS Score: %0.45
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1472
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or p... Read more
- EPSS Score: %3.06
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0799
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 resp... Read more
- EPSS Score: %0.12
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0798
The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by lever... Read more
- EPSS Score: %0.59
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-2828
CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authenticated users to obtain administrative privileges via crafted object data.... Read more
- EPSS Score: %0.53
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2827
Cross-site scripting (XSS) vulnerability in CA Spectrum 9.2.x and 9.3.x before 9.3 H02 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.22
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1773
Cross-site scripting (XSS) vulnerability in asdoc/templates/index.html in Apache Flex before 4.14.1 allows remote attackers to inject arbitrary web script or HTML by providing a crafted URI to JavaScript code generated by the asdoc component.... Read more
Affected Products : flex- EPSS Score: %1.28
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-0905
Cross-site request forgery (CSRF) vulnerability in bBlog allows remote attackers to hijack the authentication of arbitrary users.... Read more
Affected Products : bblog- EPSS Score: %0.17
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0876
Multiple cross-site scripting (XSS) vulnerabilities in the print_language_selectbox function in classes/adminpage.inc.php in Saurus CMS Community Edition before 4.7 2015-02-04 allow remote attackers to inject arbitrary web script or HTML via unspecified v... Read more
Affected Products : saurus_cms- EPSS Score: %0.32
- Published: Apr. 07, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0690
Cross-site scripting (XSS) vulnerability in the HTML help system on Cisco Wireless LAN Controller (WLC) devices before 8.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCun95178.... Read more
Affected Products : wireless_lan_controller_software- EPSS Score: %0.26
- Published: Apr. 07, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-2824
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits action to sam-ajax.php; the (2) cstr parameter in a loa... Read more
Affected Products : simple_ads_manager- EPSS Score: %12.08
- Published: Apr. 06, 2015
- Modified: Apr. 12, 2025