Latest CVE Feed
-
6.8
MEDIUMCVE-2015-5624
Buffer overflow in the ExecCall method in c2lv6.ocx in the FreeBit ELPhoneBtnV6 ActiveX control allows remote attackers to execute arbitrary code via a crafted HTML document, related to the discontinued "Click to Live" service.... Read more
Affected Products : elphonebtnv6_activex_control- Published: Sep. 07, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2989
Cross-site scripting (XSS) vulnerability in index.php in LEMON-S PHP Twit BBS allows remote attackers to inject arbitrary web script or HTML via the imagetitle parameter.... Read more
Affected Products : twit_bbs- Published: Sep. 07, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6826
The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other ... Read more
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6825
The ff_frame_thread_init function in libavcodec/pthread_frame.c in FFmpeg before 2.7.2 mishandles certain memory-allocation failures, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other im... Read more
Affected Products : ffmpeg- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6824
The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does not initialize certain pixbuf data structures, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impact vi... Read more
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6823
The allocate_buffers function in libavcodec/alac.c in FFmpeg before 2.7.2 does not initialize certain context data, which allows remote attackers to cause a denial of service (segmentation violation) or possibly have unspecified other impact via crafted A... Read more
Affected Products : ffmpeg- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6822
The destroy_buffers function in libavcodec/sanm.c in FFmpeg before 2.7.2 does not properly maintain height and width values in the video context, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or ... Read more
Affected Products : ffmpeg- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6821
The ff_mpv_common_init function in libavcodec/mpegvideo.c in FFmpeg before 2.7.2 does not properly maintain the encoding context, which allows remote attackers to cause a denial of service (invalid pointer access) or possibly have unspecified other impact... Read more
Affected Products : ffmpeg- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6820
The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax element before proceeding with Spectral Band Replication calculations, which allows remote attackers to cause a denial of service (out-o... Read more
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6819
Multiple integer underflows in the ff_mjpeg_decode_frame function in libavcodec/mjpegdec.c in FFmpeg before 2.7.2 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted MJPEG ... Read more
Affected Products : ffmpeg- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6818
The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (aka image header) chunk in a PNG image, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possib... Read more
- Published: Sep. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2986
Cross-site scripting (XSS) vulnerability in rakuto.net hitSuji (rktSNS2) 0.2.2b allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : rktsns2- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2985
Cross-site scripting (XSS) vulnerability in guide-park.com BBS X102 1.03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : bbs_x102- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-6276
Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insufficient access control, which allows remote attackers to obtain cleartext versions of HTTPS traffic or spoof devices via a direct reques... Read more
- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-5986
openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.... Read more
- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-5722
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in t... Read more
- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2991
Buffer overflow in NScripter before 3.00 allows remote attackers to execute arbitrary code via crafted save data.... Read more
Affected Products : nscripter- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-2990
Directory traversal vulnerability in zhtml.cgi in NEOJAPAN desknet NEO 2.0R1.0 through 2.5R1.4 allows remote authenticated users to read arbitrary files via a crafted parameter.... Read more
Affected Products : desknet_neo- Published: Sep. 05, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6812
Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause a denial of service (loop and memory consumption) via a crafted URL.... Read more
Affected Products : invision_power_board- Published: Sep. 04, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6811
SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.xml.... Read more
- Published: Sep. 04, 2015
- Modified: Apr. 12, 2025