Latest CVE Feed
-
3.5
LOWCVE-2014-6568
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.... Read more
Affected Products : ubuntu_linux fedora debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_server_tus mysql enterprise_linux_eus +6 more products- EPSS Score: %0.29
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2014-6567
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the p... Read more
Affected Products : database_server- EPSS Score: %7.05
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-6566
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 allows remote authenticated users to affect integrity via unknown vectors related to Portal.... Read more
Affected Products : peoplesoft_products- EPSS Score: %0.15
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-6565
Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Portal SEC.... Read more
Affected Products : jd_edwards_enterpriseone_tools- EPSS Score: %0.68
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2014-6556
Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors relate... Read more
Affected Products : e-business_suite- EPSS Score: %0.38
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-6549
Unspecified vulnerability in Oracle Java SE 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.... Read more
- EPSS Score: %1.07
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2014-6548
Unspecified vulnerability in the Oracle SOA Suite component in Oracle Fusion Middleware 11.1.1.7 allows local users to affect confidentiality, integrity, and availability via vectors related to B2B Engine.... Read more
Affected Products : fusion_middleware- EPSS Score: %0.09
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
6.3
MEDIUMCVE-2014-6541
Unspecified vulnerability in the Recovery component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenticated users to affect confidentiality via vectors related to DBMS_IR.... Read more
Affected Products : database_server- EPSS Score: %0.19
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0867
Directory traversal vulnerability in SYNCK GRAPHICA Download Log CGI 3.0 and earlier allows remote attackers to read arbitrary files via a crafted filename.... Read more
Affected Products : download_log_cgi- EPSS Score: %0.24
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-0516
Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL.... Read more
- EPSS Score: %21.44
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-0515
Unrestricted file upload vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to execute arbitrary code by uploading and then accessing an executable file.... Read more
- EPSS Score: %0.93
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0514
EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access to conduct a decryption attack.... Read more
- EPSS Score: %18.28
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-0513
Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging privileged acc... Read more
- EPSS Score: %0.18
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9598
The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file.... Read more
Affected Products : vlc_media_player- EPSS Score: %11.38
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9597
The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file.... Read more
Affected Products : vlc_media_player- EPSS Score: %6.49
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2014-9226
The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows local users to bypass intended Protection Policies via unspecified vectors.... Read more
- EPSS Score: %1.33
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-9225
The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server in... Read more
- EPSS Score: %10.12
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-9224
Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x th... Read more
- EPSS Score: %3.98
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8914
Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vu... Read more
Affected Products : business_process_manager- EPSS Score: %0.30
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8913
Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vu... Read more
Affected Products : business_process_manager- EPSS Score: %0.23
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025