Latest CVE Feed
-
5.0
MEDIUMCVE-2015-1593
The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift operations, which makes it easier for attackers to bypass the ASLR protection mechanism by predicting the... Read more
Affected Products : linux_kernel- Published: Mar. 16, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-1421
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the Linux kernel before 3.18.8 allows remote attackers to cause a denial of service (slab corruption and panic) or possibly have unspecified other impact by triggeri... Read more
- Published: Mar. 16, 2015
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2015-1420
Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a fil... Read more
- Published: Mar. 16, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-0274
The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by le... Read more
Affected Products : linux_kernel- Published: Mar. 16, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2014-8173
The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUMA systems does not properly determine whether a Page Middle Directory (PMD) entry is a transparent huge-table entry, which allows local... Read more
Affected Products : linux_kernel- Published: Mar. 16, 2015
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2014-8172
The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inappropriate locking approach, which allows local users to cause a denial of service (soft lockup or system crash) via unspecified use of ... Read more
Affected Products : linux_kernel- Published: Mar. 16, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-8159
The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physic... Read more
- Published: Mar. 16, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2014-7822
The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a single file, which allows local users to cause a denial of service (system crash) or possibly have unspecifi... Read more
Affected Products : linux_kernel- Published: Mar. 16, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2015-2304
Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.... Read more
- Published: Mar. 15, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2107
HP Operations Manager i Management Pack 1.x before 1.01 for SAP allows local users to execute OS commands by leveraging SAP administrative privileges.... Read more
- Published: Mar. 14, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-0982
Buffer overflow in an unspecified DLL in Schneider Electric Pelco DS-NVs before 7.8.90 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : pelco_ds-nv- Published: Mar. 14, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-0981
The SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to bypass authentication and read or write to arbitrary database fields via unspecified vectors.... Read more
Affected Products : bacnet_opc_server- Published: Mar. 14, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-0980
Format string vulnerability in BACnOPCServer.exe in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to execute arbitrary code via format string specifiers in a request.... Read more
Affected Products : bacnet_opc_server- Published: Mar. 14, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-0979
Heap-based buffer overflow in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to execute arbitrary code via a crafted packet.... Read more
Affected Products : bacnet_opc_server- Published: Mar. 14, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2015-0978
Multiple untrusted search path vulnerabilities in (1) EQATEC.Analytics.Monitor.Win32_vc100.dll and (2) EQATEC.Analytics.Monitor.Win32_vc100-x64.dll in Elipse E3 4.5.232 through 4.6.161 allow local users to gain privileges via a Trojan horse DLL in an unsp... Read more
Affected Products : e3- Published: Mar. 14, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-0660
Cisco Virtual TelePresence Server Software does not properly restrict use of the serial port, which allows local users to execute arbitrary OS commands as root by leveraging vSphere controller administrative privileges, aka Bug ID CSCus61123.... Read more
Affected Products : telepresence_server_software- Published: Mar. 14, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-9207
Untrusted search path vulnerability in CmnView.exe in CIMON CmnView 2.14.0.1 and 3.x before UltimateAccess 3.02 allows local users to gain privileges via a Trojan horse DLL in the current working directory.... Read more
- Published: Mar. 14, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-9206
Stack-based buffer overflow in Device Type Manager (DTM) 3.1.6 and earlier for Schneider Electric Invensys SRD Control Valve Positioner devices 960 and 991 allows local users to gain privileges via a malformed DLL file.... Read more
Affected Products : device_type_manager- Published: Mar. 14, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-7885
Multiple unspecified vulnerabilities in HP ArcSight Enterprise Security Manager (ESM) before 6.8c have unknown impact and remote attack vectors.... Read more
- Published: Mar. 14, 2015
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2014-7884
Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors.... Read more
Affected Products : arcsight_logger- Published: Mar. 14, 2015
- Modified: Apr. 12, 2025