Latest CVE Feed
-
6.8
MEDIUMCVE-2015-1153
WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabilit... Read more
- Published: May. 08, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-1152
WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerabilit... Read more
- Published: May. 08, 2015
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2015-3610
The Siemens HomeControl for Room Automation application before 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information or modify data via a crafted c... Read more
Affected Products : homecontrol_for_room_automation- Published: May. 07, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-0716
Cross-site request forgery (CSRF) vulnerability in the CUCReports page in Cisco Unity Connection 11.0(0.98000.225) and 11.0(0.98000.332) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut33659.... Read more
Affected Products : unity_connection- Published: May. 07, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-0715
SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and CSCut33608.... Read more
- Published: May. 07, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-0701
Cisco UCS Central Software before 1.3(1a) allows remote attackers to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCut46961.... Read more
Affected Products : unified_computing_system_central_software- Published: May. 07, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-0538
ftagent.exe in EMC AutoStart 5.4.x and 5.5.x before 5.5.0.508 HF4 allows remote attackers to execute arbitrary commands via crafted packets.... Read more
Affected Products : autostart- Published: May. 07, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0531
EMC SourceOne Email Management before 7.2 does not have a lockout mechanism for invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.... Read more
Affected Products : sourceone_email_management- Published: May. 07, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0714
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse Server 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCut53595.... Read more
Affected Products : finesse- Published: May. 02, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3633
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via vectors related to digital signatures.... Read more
- Published: May. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3632
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.... Read more
- Published: May. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3446
The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a crafted plugin configuration file (.cfg).... Read more
Affected Products : unified_security_management- Published: May. 01, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-3435
Samsung Security Manager (SSM) before 1.31 allows remote attackers to execute arbitrary code by uploading a file with an HTTP (1) PUT or (2) MOVE request.... Read more
Affected Products : samsung_security_manager- Published: May. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3337
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : elasticsearch- Published: May. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3153
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.... Read more
- Published: May. 01, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2248
Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for reques... Read more
- Published: May. 01, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-0257
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files i... Read more
Affected Products : enterprise_virtualization_manager- Published: May. 01, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-0237
Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote authenticated users to cause a denial of service (prevent host start) by crea... Read more
Affected Products : enterprise_virtualization_manager- Published: May. 01, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-8361
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.... Read more
Affected Products : dir-615_firmware dir-605l_firmware dir-619l_firmware dir-615 dir-905l_firmware dir-600l_firmware realtek_sdk dir-809_firmware wf800hp_firmware dir-605l +41 more products- Actively Exploited
- Published: May. 01, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3598
The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.... Read more
- Published: May. 01, 2015
- Modified: Apr. 12, 2025