Latest CVE Feed
-
6.8
MEDIUMCVE-2015-2770
Cross-site request forgery (CSRF) vulnerability in the command line page in Websense TRITON V-Series appliances before 8.0.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.... Read more
Affected Products : v-series_appliances- EPSS Score: %0.12
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2769
Multiple cross-site request forgery (CSRF) vulnerabilities in the Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.... Read more
Affected Products : triton_ap_email- EPSS Score: %0.12
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2768
Cross-site scripting (XSS) vulnerability in Websense TRITON AP-EMAIL before 8.0.0 and V-Series 7.7 appliances allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.26
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-2767
Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."... Read more
Affected Products : triton_ap_email- EPSS Score: %0.38
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2766
The Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allows attackers to have unspecified impact via a brute force attack.... Read more
Affected Products : triton_ap_email- EPSS Score: %0.26
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2765
The Email Security Gateway in Websense TRITON AP-EMAIL before 8.0.0 allows remote attackers to conduct clickjacking attacks via unspecified vectors.... Read more
Affected Products : triton_ap_email- EPSS Score: %0.22
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2764
Multiple cross-site scripting (XSS) vulnerabilities in Websense TRITON AP-DATA before 8.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the DSS (1) Mobile or (2) DLP report catalog.... Read more
Affected Products : triton_ap_data- EPSS Score: %0.26
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-2763
Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to port 17703.... Read more
Affected Products : triton_ap_email- EPSS Score: %0.38
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2762
Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentication.... Read more
Affected Products : triton_ap_web- EPSS Score: %0.23
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2761
Cross-site scripting (XSS) vulnerability in the Exceptions and Scanning Exceptions Pages in Websense TRITON AP-WEB before 8.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.26
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2760
Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : data_loss_prevention_endpoint- EPSS Score: %0.18
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2759
Multiple cross-site request forgery (CSRF) vulnerabilities in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allow remote attackers to hijack the authentication of users for requests that (1) obta... Read more
Affected Products : data_loss_prevention_endpoint- EPSS Score: %0.12
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-2758
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain sensitive information, modify the database, or possibly have other unspecified impact via a crafted URL.... Read more
Affected Products : data_loss_prevention_endpoint- EPSS Score: %0.39
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-2757
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to cause a denial of service (database lock or license corruption) via unspecified vectors.... Read more
Affected Products : data_loss_prevention_endpoint- EPSS Score: %0.40
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-2157
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.... Read more
- EPSS Score: %0.27
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-9712
Websense TRITON V-Series appliances before 7.8.3 Hotfix 03 and 7.8.4 before Hotfix 01 allow remote administrators to read arbitrary files and obtain passwords via a crafted path.... Read more
Affected Products : v-series_appliances- EPSS Score: %0.27
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-8121
DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing ... Read more
- EPSS Score: %2.53
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3619
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.... Read more
- EPSS Score: %1.11
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-2184
Movable Type before 5.2.6 does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via the comment_state parameter.... Read more
Affected Products : movable_type- EPSS Score: %3.20
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2748
Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sensitive information via a direct request to a (1) Web Security incident report or the (2) Explorer configuration (we... Read more
- EPSS Score: %0.44
- Published: Mar. 26, 2015
- Modified: Apr. 12, 2025