| apache — ambari |
Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call. |
2015-11-02 |
5.5 |
CVE-2015-1775 CONFIRM MLIST |
| apache — ambari |
Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related to changing passwords. |
2015-11-02 |
6.5 |
CVE-2015-3270 CONFIRM MLIST |
| apache — ambari |
Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI parameter. |
2015-11-02 |
5.8 |
CVE-2015-5210 CONFIRM MLIST |
| arm — mbed_tls |
Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long hostname to the server name indication (SNI) extension, which is not properly handled when creating a ClientHello message. NOTE: this identifier has been SPLIT per ADT3 due to different affected version ranges. See CVE-2015-8036 for the session ticket issue that was introduced in 1.3.0. |
2015-11-02 |
6.8 |
CVE-2015-5291 CONFIRM MISC MISC FEDORA |
| arm — mbed_tls |
Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the session ticket extension, which is not properly handled when creating a ClientHello message to resume a session. NOTE: this identifier was SPLIT from CVE-2015-5291 per ADT3 due to different affected version ranges. |
2015-11-02 |
6.8 |
CVE-2015-8036 CONFIRM MISC MISC FEDORA |
| cisco — mobility_services_engine |
Cisco Mobility Services Engine (MSE) through 8.0.120.7 uses weak permissions for unspecified binary files, which allows local users to obtain root privileges by writing to a file, aka Bug ID CSCuv40504. |
2015-11-06 |
6.9 |
CVE-2015-4282 CISCO |
| cisco — mobility_services_engine |
The default configuration of sshd_config in Cisco Mobility Services Engine (MSE) through 8.0.120.7 allows logins by the oracle account, which makes it easier for remote attackers to obtain access by entering this account’s hardcoded password in an SSH session, aka Bug ID CSCuv40501. |
2015-11-06 |
6.5 |
CVE-2015-6316 CISCO |
| cisco — ios |
The SIP implementation in Cisco IOS 15.5(3)M on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service via crafted SIP messages, aka Bug ID CSCuv79202. |
2015-10-31 |
5.0 |
CVE-2015-6343 CISCO |
| cisco — unified_computing_system_(managed) |
The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version information by visiting an unspecified URL, aka Bug ID CSCuw87226. |
2015-11-03 |
5.0 |
CVE-2015-6355 CISCO |
| cisco — socialminer |
Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco Social Miner 10.0(1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuw60212. |
2015-11-03 |
4.3 |
CVE-2015-6356 CISCO |
| dell — sonicwall_totalsecure_tz_100_firmware |
Dell SonicWall TotalSecure TZ 100 devices with firmware before 5.9.1.0-22o allow remote attackers to cause a denial of service via a crafted packet. |
2015-11-06 |
5.0 |
CVE-2015-7770 JVNDB JVN |
| fortinet — fortimanager_firmware |
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SOMVpnSSLPortalDialog or (2) FGDMngUpdHistory. |
2015-11-02 |
4.3 |
CVE-2015-8037 CONFIRM |
| fortinet — fortimanager_firmware |
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) sharedjobmanager or (2) SOMServiceObjDialog. |
2015-11-02 |
4.3 |
CVE-2015-8038 CONFIRM |
| google — android |
mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23905951, 23912202, 23953967, 23696300, 23600291, 23756261, 23541506, 23284974, 23542351, and 23542352, a different vulnerability than CVE-2015-8074. |
2015-11-03 |
5.0 |
CVE-2015-6611 MLIST |
| google — android |
Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port, and consequently gain privileges, via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24371736. |
2015-11-03 |
5.1 |
CVE-2015-6613 MLIST |
| google — android |
Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently bypass intended network-interface restrictions, perform expensive data transfers, or cause a denial of service (call-reception outage or mute manipulation), via a crafted application, aka internal bug 21900139. |
2015-11-03 |
5.8 |
CVE-2015-6614 MLIST |
| google — android |
mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, aka internal bugs 23540907 and 23515142, a different vulnerability than CVE-2015-6611. |
2015-11-03 |
5.0 |
CVE-2015-8074 MLIST |
| hp — arcsight_smartconnectors |
HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate. |
2015-11-03 |
6.8 |
CVE-2015-2902 CERT-VN HP |
| hp — arcsight_smartconnectors |
The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password. |
2015-11-03 |
6.9 |
CVE-2015-2903 CERT-VN HP |
| hp — arcsight_logger |
HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach. |
2015-11-03 |
5.0 |
CVE-2015-6029 CERT-VN HP |
| ibm — infosphere_information_server |
IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain sensitive information via unspecified vectors. |
2015-11-03 |
5.5 |
CVE-2015-5021 CONFIRM AIXAPAR |
| isucon — isucon_5_qualifier_eventapp |
eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper popen calls, which allows remote attackers to execute arbitrary commands via an HTTP request that includes shell metacharacters in an argument to a “gcloud compute” command. |
2015-11-03 |
6.5 |
CVE-2015-5673 CONFIRM CONFIRM JVNDB JVN |
| miniupnp_project — miniupnp |
Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an “oversized” XML element name. |
2015-11-02 |
6.8 |
CVE-2015-6031 CONFIRM CONFIRM UBUNTU UBUNTU DEBIAN MISC |
| mozilla — firefox |
Mozilla Firefox before 42.0, when NTLM v1 is enabled for HTTP authentication, allows remote attackers to obtain sensitive hostname information by constructing a crafted web site that sends an NTLM request and reads the Workstation field of an NTLM type 3 message. |
2015-11-05 |
4.3 |
CVE-2015-4515 CONFIRM CONFIRM |
| mozilla — firefox |
The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL. |
2015-11-05 |
4.3 |
CVE-2015-4518 CONFIRM CONFIRM CONFIRM |
| mozilla — firefox |
Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which allows remote attackers to spoof the address bar via crafted JavaScript code. |
2015-11-05 |
4.3 |
CVE-2015-7185 CONFIRM CONFIRM |
| mozilla — firefox |
Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigger (1) a download or (2) cached profile-data reading via a file: URL in a saved HTML document. |
2015-11-05 |
4.3 |
CVE-2015-7186 CONFIRM CONFIRM |
| mozilla — firefox |
The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a “script: false” panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension. |
2015-11-05 |
4.3 |
CVE-2015-7187 CONFIRM CONFIRM |
| mozilla — firefox |
Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code. |
2015-11-05 |
6.8 |
CVE-2015-7189 CONFIRM CONFIRM |
| mozilla — firefox |
The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access this URL in a privileged context in conjunction with the crash reporter, which allows attackers to read log files and visit file: URLs of HTML documents via a crafted application. |
2015-11-05 |
5.0 |
CVE-2015-7190 CONFIRM CONFIRM |
| mozilla — firefox |
Mozilla Firefox before 42.0 on Android improperly restricts URL strings in intents, which allows attackers to conduct cross-site scripting (XSS) attacks via vectors involving an intent: URL and fallback navigation, aka “Universal XSS (UXSS).” |
2015-11-05 |
4.3 |
CVE-2015-7191 CONFIRM CONFIRM |
| mozilla — firefox |
The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which allows remote attackers to obtain sensitive information via vectors involving a redirect. |
2015-11-05 |
5.0 |
CVE-2015-7195 CONFIRM CONFIRM |
| mozilla — firefox |
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, when a Java plugin is enabled, allow remote attackers to cause a denial of service (incorrect garbage collection and application crash) or possibly execute arbitrary code via a crafted Java applet that deallocates an in-use JavaScript wrapper. |
2015-11-05 |
6.8 |
CVE-2015-7196 CONFIRM CONFIRM |
| mozilla — firefox |
Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web worker to create a WebSocket object, which allows remote attackers to bypass intended mixed-content restrictions via crafted JavaScript code. |
2015-11-05 |
5.0 |
CVE-2015-7197 CONFIRM CONFIRM |
| oxwall — oxwall |
Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the authentication of administrators for requests that (1) put the website under maintenance via the maintenance_enable parameter or (2) conduct cross-site scripting (XSS) attacks via the maintenance_text parameter to admin/pages/maintenance. |
2015-11-02 |
6.8 |
CVE-2015-5534 MISC BUGTRAQ MISC |
| samsung — smartviewer |
Samsung SmartViewer allow remote attackers to execute arbitrary code via unspecified vectors to the (1) DVRSetupSave method in the STWAxConfig control or (2) SendCustomPacket method in the STWAxConfigNVR control, which trigger an untrusted pointer dereference. |
2015-11-02 |
6.8 |
CVE-2015-8039 MISC MISC |
| samsung — smartviewer |
The rtsp_getdlsendtime method in the CNC_Ctrl control in Samsung SmartViewer allows remote attackers to execute arbitrary code via an index value. |
2015-11-02 |
6.8 |
CVE-2015-8040 MISC |
| sap — 3d_visual_enterprise_viewer |
Multiple buffer overflows in SAP 3D Visual Enterprise Viewer (VEV) allow remote attackers to execute arbitrary code via a crafted (1) 3DM or (2) Flic Animation file. |
2015-10-30 |
6.8 |
CVE-2015-8028 MISC MISC |
| sap — 3d_visual_enterprise_viewer |
SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a crafted Filmbox document, which triggers memory corruption. |
2015-10-30 |
6.8 |
CVE-2015-8029 MISC |
| sap — 3d_visual_enterprise_viewer |
SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a crafted (1) U3D, (2) LWO, (3) JPEG2000, or (4) FBX file, aka “Out-Of-Bounds Indexing” vulnerabilities. |
2015-10-30 |
6.8 |
CVE-2015-8030 MISC MISC MISC MISC |
| xen — xen |
Race condition in the relinquish_memory function in arch/arm/domain.c in Xen 4.6.x and earlier allows local domains with partial management control to cause a denial of service (host crash) via vectors involving the destruction of a domain and using XENMEM_decrease_reservation to reduce the memory of the domain. |
2015-10-30 |
4.7 |
CVE-2015-7814 CONFIRM |
| xen — xen |
Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of “teardowns” of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcpus hypercall or the xenoprofile state vcpu pointer array allocated using the (2) XENOPROF_get_buffer or (3) XENOPROF_set_passive hypercall. |
2015-10-30 |
4.9 |
CVE-2015-7969 CONFIRM CONFIRM |
| xen — xen |
The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a “time-consuming linear scan,” related to Populate-on-Demand. |
2015-10-30 |
4.9 |
CVE-2015-7970 CONFIRM |