Latest CVE Feed
-
2.1
LOWCVE-2014-5400
The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file.... Read more
Affected Products : mednet- EPSS Score: %0.06
- Published: Apr. 03, 2015
- Modified: Apr. 12, 2025
-
6.3
MEDIUMCVE-2015-0687
The SNMP implementation in Cisco IOS 15.1(2)SG4 on Catalyst 4500 devices, when single-switch Virtual Switching System (VSS) is configured, allows remote authenticated users to cause a denial of service (device crash) by performing SNMP polling, aka Bug ID... Read more
- EPSS Score: %0.34
- Published: Apr. 03, 2015
- Modified: Apr. 12, 2025
-
6.3
MEDIUMCVE-2015-0686
The SNMP implementation in Cisco NX-OS 6.1(2)I2(3) on Nexus 9000 devices, when a Reset High Availability (HA) policy is configured, allows remote authenticated users to cause a denial of service (device reload) via unspecified vectors, aka Bug ID CSCuq922... Read more
Affected Products : nx-os nexus_9000 nexus_93120tx nexus_93128tx nexus_9332pq nexus_9336pq_aci_spine nexus_9372px nexus_9372tx- EPSS Score: %0.77
- Published: Apr. 03, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-0685
Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers to cause a denial of service (device hang) via crafted IP packets, aka Bug ID CSCub31873.... Read more
- EPSS Score: %0.43
- Published: Apr. 03, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1234
Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact by manipulating OpenGL ES commands.... Read more
- EPSS Score: %2.01
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1233
Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
- EPSS Score: %28.72
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-2821
TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other editors via unspecified vectors.... Read more
Affected Products : neos- EPSS Score: %0.32
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2820
Buffer overflow in XcListener in SAP Afaria 7.0.6001.5 allows remote attackers to cause a denial of service (process termination) via a crafted request, aka SAP Security Note 2132584.... Read more
Affected Products : afaria- EPSS Score: %3.87
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2819
SAP Sybase SQL Anywhere 11 and 16 allows remote attackers to cause a denial of service (crash) via a crafted request, aka SAP Security Note 2108161.... Read more
Affected Products : sql_anywhere- EPSS Score: %3.28
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2818
XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125513.... Read more
Affected Products : mobile_platform- EPSS Score: %0.37
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2817
The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768.... Read more
Affected Products : netweaver- EPSS Score: %0.44
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-2816
The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote attackers to have unspecified impact via a crafted request, aka SAP Security Note 2134905.... Read more
Affected Products : afaria- EPSS Score: %0.76
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-2815
Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (7400.12.21.30308) allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via unspecified vec... Read more
Affected Products : netweaver- EPSS Score: %3.46
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2015-2814
SAP EMR Unwired (com.sap.mobile.healthcare.emr.v2) and Clinical Task Tracker (com.sap.mobile.healthcare.ctt) does not properly restrict access, which allows remote attackers to change the backendurl, clientid, ssourl, and infopageurl settings via unspecif... Read more
- EPSS Score: %0.46
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2813
XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125358.... Read more
Affected Products : mobile_platform- EPSS Score: %0.54
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2812
XML external entity (XXE) vulnerability in XMLValidationComponent in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2093966.... Read more
Affected Products : netweaver_enterprise_portal- EPSS Score: %0.57
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2811
XML external entity (XXE) vulnerability in ReportXmlViewer in SAP NetWeaver Portal 7.31.201109172004 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2111939.... Read more
Affected Products : netweaver_enterprise_portal- EPSS Score: %0.66
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-2756
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decod... Read more
- EPSS Score: %0.12
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2755
Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) atta... Read more
Affected Products : ab_google_map_travel- EPSS Score: %0.69
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2015-2752
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device mo... Read more
- EPSS Score: %0.12
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025