Latest CVE Feed
-
8.3
HIGHCVE-2015-2247
Unspecified vulnerability in Boosted Boards skateboards allows physically proximate attackers to modify skateboard movement, cause human injury, or cause physical damage via vectors related to an "injection attack" that blocks and hijacks a Bluetooth sign... Read more
Affected Products : boosted_boards- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-3027
Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way that triggers stack storage for stack cookie pointers, which might allow context-dependent attackers to bypass a stack-guard protection mechanism via crafted... Read more
Affected Products : xcode- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3008
Asterisk Open Source 1.8 before 1.8.32.3, 11.x before 11.17.1, 12.x before 12.8.2, and 13.x before 13.3.2 and Certified Asterisk 1.8.28 before 1.8.28-cert5, 11.6 before 11.6-cert11, and 13.1 before 13.1-cert2, when registering a SIP TLS device, does not p... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3005
Cross-site scripting (XSS) vulnerability in the Dynamic VPN in Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, and 12.3X48 before 12.3X48-D10 on SRX series devices allows remote attackers to inject arbitra... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3004
J-Web in Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D35, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D10, 12.3X48 before 12.3X48-D10, 12.2 before 12.2R9, 12.3 before 12.3R7, 13.2 before 13.2R6, 13.2X51 before 13.2X51-D20, 13.3 before... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-3003
Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D10, 13.2 before 13.2R6, 13.3 before 13.3R5, 14.1 before 14.1R3, and 14.2 before 14.2R1 allows local users to gain... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-3002
Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, and 12.3X48 before 12.3X48-D10 on SRX series devices does not properly enforce the log-out-on-disconnect feature when configured in the [system port console]... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-2806
Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2779
Stack consumption vulnerability in the message splitting functionality in Quassel before 0.12-rc1 allows remote attackers to cause a denial of service (uncontrolled recursion) via a crafted massage.... Read more
Affected Products : quassel- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2778
Quassel before 0.12-rc1 uses an incorrect data-type size when splitting a message, which allows remote attackers to cause a denial of service (crash) via a long CTCP query containing only multibyte characters.... Read more
Affected Products : quassel- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2295
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deletefi... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-1842
The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.... Read more
Affected Products : openstack- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-1415
The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading the fil... Read more
Affected Products : freebsd- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1149
Integer overflow in the simulator in Swift in Apple Xcode before 6.3 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact by triggering an incorrect result of a type conversion.... Read more
Affected Products : xcode- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-1148
Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-dependent attackers to obtain sensitive information by reading this file.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-1147
Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-1146
The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different vulnerability than CVE-2015-1145.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-1145
The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different vulnerability than CVE-2015-1146.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-1144
Buffer overflow in the UniformTypeIdentifiers component in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted Uniform Type Identifier.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-1143
LaunchServices in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted localized string, related to a "type confusion" issue.... Read more
- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025