Latest CVE Feed
-
6.1
MEDIUMCVE-2015-0679
The web-authentication functionality on Cisco Wireless LAN Controller (WLC) devices 7.3(103.8) and 7.4(110.0) allows remote attackers to cause a denial of service (device reload) via a malformed password, aka Bug ID CSCui57980.... Read more
Affected Products : wireless_lan_controller_software- Published: Mar. 28, 2015
- Modified: Apr. 12, 2025
-
7.9
HIGHCVE-2015-0658
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the lo... Read more
Affected Products : nx-os nexus_7000 nx-os nexus_5010 nexus_5020 nexus_5548p nexus_5548up nexus_5596up nexus_3048 nexus_3548 +26 more products- Published: Mar. 28, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2773
SVM in Websense TRITON V-Series appliances before 8.0.0 allows attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : v-series_appliances- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-2772
SVM in Websense TRITON V-Series appliances before 8.0.0 allows attackers to upload arbitrary files via unspecified vectors.... Read more
Affected Products : v-series_appliances- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2771
The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers to obtain sensitive information via unspecified vectors.... Read more
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2770
Cross-site request forgery (CSRF) vulnerability in the command line page in Websense TRITON V-Series appliances before 8.0.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.... Read more
Affected Products : v-series_appliances- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2769
Multiple cross-site request forgery (CSRF) vulnerabilities in the Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.... Read more
Affected Products : triton_ap_email- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2768
Cross-site scripting (XSS) vulnerability in Websense TRITON AP-EMAIL before 8.0.0 and V-Series 7.7 appliances allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-2767
Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."... Read more
Affected Products : triton_ap_email- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2766
The Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allows attackers to have unspecified impact via a brute force attack.... Read more
Affected Products : triton_ap_email- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2765
The Email Security Gateway in Websense TRITON AP-EMAIL before 8.0.0 allows remote attackers to conduct clickjacking attacks via unspecified vectors.... Read more
Affected Products : triton_ap_email- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2764
Multiple cross-site scripting (XSS) vulnerabilities in Websense TRITON AP-DATA before 8.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the DSS (1) Mobile or (2) DLP report catalog.... Read more
Affected Products : triton_ap_data- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-2763
Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to port 17703.... Read more
Affected Products : triton_ap_email- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-2762
Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentication.... Read more
Affected Products : triton_ap_web- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2761
Cross-site scripting (XSS) vulnerability in the Exceptions and Scanning Exceptions Pages in Websense TRITON AP-WEB before 8.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2760
Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : data_loss_prevention_endpoint- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-2759
Multiple cross-site request forgery (CSRF) vulnerabilities in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allow remote attackers to hijack the authentication of users for requests that (1) obta... Read more
Affected Products : data_loss_prevention_endpoint- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-2758
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain sensitive information, modify the database, or possibly have other unspecified impact via a crafted URL.... Read more
Affected Products : data_loss_prevention_endpoint- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-2757
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to cause a denial of service (database lock or license corruption) via unspecified vectors.... Read more
Affected Products : data_loss_prevention_endpoint- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-2157
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.... Read more
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025