Latest CVE Feed
-
6.8
MEDIUMCVE-2015-3349
Multiple cross-site request forgery (CSRF) vulnerabilities in the Htaccess module before 7.x-2.3 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) deploy or (2) delete an .htaccess file via unspecified ... Read more
Affected Products : htaccess- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-3348
Cross-site scripting (XSS) vulnerability in the Cloudwords for Multilingual Drupal module before 7.x-2.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.... Read more
Affected Products : cloudwords_for_multilingual- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3347
Cross-site request forgery (CSRF) vulnerability in the Cloudwords for Multilingual Drupal module before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of unspecified victims via an unknown menu callback.... Read more
Affected Products : cloudwords_for_multilingual- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-3346
SQL injection vulnerability in the WikiWiki module before 6.x-1.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : wikiwiki- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-3345
SQL injection vulnerability in the PHPlist Integration Module before 6.x-1.7 for Drupal allows remote administrators to execute arbitrary SQL commands via unspecified vectors, related to the "phpList database."... Read more
Affected Products : phplist_integration- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-3344
Cross-site scripting (XSS) vulnerability in the Course module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.... Read more
Affected Products : course- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-3343
Cross-site request forgery (CSRF) vulnerability in the OPAC module before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of unspecified victims for requests that remove a mapping via unknown vectors.... Read more
Affected Products : opac- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-3342
Open redirect vulnerability in the Ubercart Currency Conversion module before 6.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination query parameter.... Read more
Affected Products : ubercart_currency_conversion- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-0135
IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of service (integer truncation and application crash) via a crafted GIF image, aka SPR KLYH9T7NT9.... Read more
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2014-9718
The (1) BMDMA and (2) AHCI HBA interfaces in the IDE functionality in QEMU 1.0 through 2.1.3 have multiple interpretations of a function's return value, which allows guest OS users to cause a host OS denial of service (memory consumption or infinite loop,... Read more
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-2825
Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct re... Read more
Affected Products : simple_ads_manager- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-5370
Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows remote attackers to read or possibly delete arbitrary files via a .. (dot dot) in the QUERY_STRING to cfc... Read more
Affected Products : bluedragon- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-5361
Multiple cross-site request forgery (CSRF) vulnerabilities in Landesk Management Suite 9.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) start, (2) stop, or (3) restart services via a request to re... Read more
Affected Products : landesk_management_suite- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2015-2042
net/rds/sysctl.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry.... Read more
Affected Products : linux_kernel- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2015-2041
net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl... Read more
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-1701
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerab... Read more
- Actively Exploited
- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0703
Cross-site scripting (XSS) vulnerability in the administrative web interface in Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCus95857.... Read more
Affected Products : unified_meetingplace- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-0702
Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated users to execute arbitrary code by using the languageShortName parameter to upload a file that provides s... Read more
Affected Products : unified_meetingplace- Published: Apr. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3336
Google Chrome before 42.0.2311.90 does not always ask the user before proceeding with CONTENT_SETTINGS_TYPE_FULLSCREEN and CONTENT_SETTINGS_TYPE_MOUSELOCK changes, which allows user-assisted remote attackers to cause a denial of service (UI disruption) by... Read more
- Published: Apr. 19, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-3335
The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandbox_linux/nacl_sandbox_linux.cc in Google Chrome before 42.0.2311.90 does not have RLIMIT_AS and RLIMIT_DATA limits for Native Client (aka NaCl) processes, which might make ... Read more
- Published: Apr. 19, 2015
- Modified: Apr. 12, 2025