Latest CVE Feed
-
10.0
HIGHCVE-2015-0339
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more
- EPSS Score: %9.33
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-0338
Integer overflow in Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code via unspecified vectors.... Read more
- EPSS Score: %4.01
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0337
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows remote attackers to bypass the Same Origin Policy via unspecified vectors.... Read more
- EPSS Score: %0.68
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-0336
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-... Read more
- EPSS Score: %91.74
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-0335
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more
- EPSS Score: %9.33
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-0334
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-... Read more
- EPSS Score: %5.02
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-0333
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more
- EPSS Score: %9.33
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-0332
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more
- EPSS Score: %8.65
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2091
The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when "GnuTLSClientVerify require" is set, which allows remote attackers to spoof clients via a crafted certificate.... Read more
Affected Products : mod-gnutls- EPSS Score: %0.71
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1782
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.... Read more
- EPSS Score: %4.13
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-2264
Multiple untrusted search path vulnerabilities in (1) EQATEC.Analytics.Monitor.Win32_vc100.dll and (2) EQATEC.Analytics.Monitor.Win32_vc100-x64.dll in Telerik Analytics Monitor Library before 3.2.125 allow local users to gain privileges via a Trojan horse... Read more
Affected Products : analytics_monitor_library- EPSS Score: %0.09
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-0654
Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to cause a denial of service (process hang) by establishing many HTTPS sessions, ak... Read more
Affected Products : intrusion_prevention_system- EPSS Score: %0.31
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-0653
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to... Read more
- EPSS Score: %7.80
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-0652
The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled ex... Read more
- EPSS Score: %0.43
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0177
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_portal- EPSS Score: %0.19
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0139
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF15 and 8.5.0 before CF05 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_portal- EPSS Score: %0.19
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0133
IBM WebSphere Commerce 7.0 Feature Pack 4 through 8 allows remote attackers to read arbitrary files and possibly obtain administrative privileges via an XML external entity declaration in conjunction with an entity reference, related to an XML External En... Read more
Affected Products : websphere_commerce- EPSS Score: %0.39
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0129
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager (RQM) 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
- EPSS Score: %0.17
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0123
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different v... Read more
Affected Products : rational_team_concert- EPSS Score: %0.19
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0122
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert 2.x and 3.x before 3.0.1.6 iFix 5, 4.x before 4.0.7 iFix3, and 5.x before 5.0.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different v... Read more
Affected Products : rational_team_concert- EPSS Score: %0.19
- Published: Mar. 13, 2015
- Modified: Apr. 12, 2025