Latest CVE Feed
-
7.5
HIGHCVE-2015-3414
SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact ... Read more
- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3310
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to th... Read more
- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3148
cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.... Read more
Affected Products : ubuntu_linux fedora debian_linux curl mac_os_x libcurl opensuse system_management_homepage- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-3145
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a co... Read more
Affected Products : ubuntu_linux fedora debian_linux curl mac_os_x libcurl opensuse solaris system_management_homepage- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-3144
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a ze... Read more
- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3143
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.... Read more
- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0846
django-markupfield before 1.3.2 uses the default docutils RESTRUCTUREDTEXT_FILTER_SETTINGS settings, which allows remote attackers to include and read arbitrary files via unspecified vectors.... Read more
Affected Products : django-markupfield- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-0297
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consu... Read more
Affected Products : jboss_operations_network- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2012-5451
Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before 2.1.0.3974 allow remote attackers to cause a denial of service (tvMobiliService service crash) via a long string in a (1) GET or (2) HEAD request to TCP port 30888.... Read more
Affected Products : tvmobili- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-2932
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web script or HTML via the selitems[] parameter in a (1) copy, (2) chmod, or (3) arch action to admin/index.php or (4) sear... Read more
Affected Products : tinywebgallery- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2012-2930
Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an adduser action to admin/index.php or (2) conduct ... Read more
Affected Products : tinywebgallery- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2011-4403
Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm action to product.php or (2) disable a ... Read more
Affected Products : zen_cart- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0911
Directory traversal vulnerability in TAGAWA Takao TransmitMail 1.0.11 through 1.5.8 allows remote attackers to read arbitrary files via vectors related to attachment handling.... Read more
Affected Products : transmitmail- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0910
Cross-site scripting (XSS) vulnerability in TAGAWA Takao TransmitMail 1.0.11 through 1.5.8 allows remote attackers to inject arbitrary web script or HTML via a crafted filename.... Read more
Affected Products : transmitmail- Published: Apr. 24, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0707
Cross-site scripting (XSS) vulnerability in Cisco FireSIGHT System Software 5.3.1.1 and 6.0.0 in FireSIGHT Management Center allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCus85425.... Read more
Affected Products : firesight_system_software- Published: Apr. 23, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-0706
Open redirect vulnerability in Cisco FireSIGHT System Software 5.3.1.1, 5.3.1.2, and 6.0.0 in FireSIGHT Management Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted HTTP header, aka Bug IDs ... Read more
Affected Products : firesight_system_software- Published: Apr. 23, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-3404
The Certify module before 6.x-2.3 for Drupal does not properly perform node access checks, which allows remote authenticated users to bypass intended access restrictions and obtain sensitive PDF certificate information via vectors related to "showing (and... Read more
Affected Products : certify- Published: Apr. 22, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-1889
The Big SQL component in IBM InfoSphere BigInsights 3.0 through 3.0.0.2 allows remote authenticated users to bypass intended HDFS data-access restrictions via (1) a crafted CREATE HADOOP TABLE statement referencing the data of an arbitrary user or (2) an ... Read more
Affected Products : infosphere_biginsights- Published: Apr. 22, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-1484
Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain privileges via a Trojan horse execut... Read more
Affected Products : workspace_streaming- Published: Apr. 22, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-3035
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmwa... Read more
Affected Products : tl-wr841n_\(9.0\)_firmware tl-wr740n_\(5.0\)_firmware archer_c5_\(1.2\)_firmware tl-wr841n_\(10.0\)_firmware tl-wr741nd_\(5.0\)_firmware tl-wr741nd_\(5.0\) tl-wdr3600_\(1.0\)_firmware archer_c7_\(2.0\)_firmware tl-wr841nd_\(10.0\)_firmware archer_c9_\(1.0\)_firmware +16 more products- Actively Exploited
- Published: Apr. 22, 2015
- Modified: Apr. 12, 2025