Search Results (Refine Search)
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2015-6556 |
EACommunicatorSrv.exe in the Framework Service in the client in Symantec Endpoint Encryption (SEE) before 11.1.0 allows remote authenticated users to discover credentials by triggering a memory dump. Published: December 18, 2015; 6:59:05 AM -0500 |
V3.x:(not available) V2.0: 2.3 LOW |
CVE-2015-6428 |
Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958. Published: December 18, 2015; 6:59:03 AM -0500 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2015-6427 |
Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka Bug ID CSCux53437. Published: December 18, 2015; 6:59:02 AM -0500 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2015-6426 |
Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitrary commands via additional parameters to an unspecified command, aka Bug ID CSCus99427. Published: December 18, 2015; 6:59:01 AM -0500 |
V3.x:(not available) V2.0: 7.2 HIGH |
CVE-2015-6424 |
The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985. Published: December 18, 2015; 6:59:00 AM -0500 |
V3.x:(not available) V2.0: 7.2 HIGH |
CVE-2015-8602 |
The Token Insert Entity module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote authenticated users with certain permissions to bypass intended access restrictions and possibly obtain sensitive information by inserting a token, which embeds a rendered entity in the main node. Published: December 17, 2015; 2:59:14 PM -0500 |
V3.x:(not available) V2.0: 3.5 LOW |
CVE-2015-8601 |
The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket for chat messages, which allows remote attackers to bypass intended access restrictions and read messages from arbitrary Chat Rooms via unspecified vectors. Published: December 17, 2015; 2:59:13 PM -0500 |
V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2015-8600 |
The SysAdminWebTool servlets in SAP Mobile Platform allow remote attackers to bypass authentication and obtain sensitive information, gain privileges, or have unspecified other impact via unknown vectors, aka SAP Security Note 2227855. Published: December 17, 2015; 2:59:12 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2015-8369 |
SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php. Published: December 17, 2015; 2:59:11 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2015-8368 |
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua. Published: December 17, 2015; 2:59:10 PM -0500 |
V3.x:(not available) V2.0: 6.0 MEDIUM |
CVE-2015-8341 |
The libxl toolstack library in Xen 4.1.x through 4.6.x does not properly release mappings of files used as kernels and initial ramdisks when managing multiple domains in the same process, which allows attackers to cause a denial of service (memory and disk consumption) by starting domains. Published: December 17, 2015; 2:59:09 PM -0500 |
V3.x:(not available) V2.0: 7.8 HIGH |
CVE-2015-8340 |
The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly release locks, which might allow guest OS administrators to cause a denial of service (deadlock or host crash) via unspecified vectors, related to XENMEM_exchange error handling. Published: December 17, 2015; 2:59:08 PM -0500 |
V3.x:(not available) V2.0: 4.7 MEDIUM |
CVE-2015-8339 |
The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain, which might allow guest OS administrators to cause a denial of service (host crash) via unspecified vectors related to domain teardown. Published: December 17, 2015; 2:59:07 PM -0500 |
V3.x:(not available) V2.0: 4.7 MEDIUM |
CVE-2015-8338 |
Xen 4.6.x and earlier does not properly enforce limits on page order inputs for the (1) XENMEM_increase_reservation, (2) XENMEM_populate_physmap, (3) XENMEM_exchange, and possibly other HYPERVISOR_memory_op suboperations, which allows ARM guest OS administrators to cause a denial of service (CPU consumption, guest reboot, or watchdog timeout and host reboot) and possibly have unspecified other impact via unknown vectors. Published: December 17, 2015; 2:59:06 PM -0500 |
V3.x:(not available) V2.0: 7.2 HIGH |
CVE-2015-8327 |
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job. Published: December 17, 2015; 2:59:05 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2015-7527 |
lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via shell metacharacters in the "Width of preview image" and possibly other input fields in the "Video Gallery Settings" page. Published: December 17, 2015; 2:59:04 PM -0500 |
V3.x:(not available) V2.0: 7.5 HIGH |
CVE-2015-7518 |
Multiple cross-site scripting (XSS) vulnerabilities in information popups in Foreman before 1.10.0 allow remote attackers to inject arbitrary web script or HTML via (1) global parameters, (2) smart class parameters, or (3) smart variables in the (a) host or (b) hostgroup edit forms. Published: December 17, 2015; 2:59:03 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2015-5277 |
The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database. Published: December 17, 2015; 2:59:02 PM -0500 |
V3.x:(not available) V2.0: 7.2 HIGH |
CVE-2015-5204 |
CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before 1.3.0 allows remote attackers to inject arbitrary headers via CRLF sequences in the filename of an uploaded file. Published: December 17, 2015; 2:59:01 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2015-4027 |
The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users to gain privileges via a command parameter in the reporttemplate property in a params JSON object to api/addScan. Published: December 17, 2015; 2:59:00 PM -0500 |
V3.x:(not available) V2.0: 7.2 HIGH |