apache — http_server |
The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400 directive specifying a local URI. |
2015-07-20 |
5.0 |
CVE-2015-0253 CONFIRM CONFIRM CONFIRM CONFIRM |
apache — http_server |
The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c. |
2015-07-20 |
5.0 |
CVE-2015-3183 CONFIRM CONFIRM CONFIRM |
apache — http_server |
The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging the presence of a module that relies on the 2.2 API behavior. |
2015-07-20 |
4.3 |
CVE-2015-3185 CONFIRM CONFIRM CONFIRM |
blackberry — blackberry_link |
mc_demux_mp4_ds.ax in an unspecified third-party codec demux in BlackBerry Link before 1.2.3.53 with installer before 1.1.0.22 allows remote attackers to execute arbitrary code via a crafted MP4 file. |
2015-07-19 |
6.8 |
CVE-2015-4111 CONFIRM |
cisco — webex_training_center |
Cross-site scripting (XSS) vulnerability in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuv01955. |
2015-07-21 |
4.3 |
CVE-2015-4246 CISCO |
cisco — prime_collaboration |
Cisco Prime Collaboration Assurance 10.0 allows remote attackers to cause a denial of service (HTTP service outage) via a crafted HTTP request, aka Bug ID CSCum38844. |
2015-07-18 |
5.0 |
CVE-2015-4280 CISCO |
cisco — webex_meetings_server |
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.5 MR1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCus56150 and CSCus56146. |
2015-07-22 |
6.8 |
CVE-2015-4281 CISCO |
cisco — ios_xr |
The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to cause a denial of service (BGP process reload) via malformed BGPv4 packets, aka Bug ID CSCur70670. |
2015-07-22 |
5.0 |
CVE-2015-4284 CISCO |
cisco — ios_xr |
The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k devices makes incorrect decisions about the opening of TCP and UDP ports during the processing of flow base entries, which allows remote attackers to cause a denial of service (resource consumption) by sending traffic to these ports continuously, aka Bug ID CSCur88273. |
2015-07-23 |
5.0 |
CVE-2015-4285 CISCO |
cisco — adaptive_security_appliance_software |
The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS content by modifying packets, aka Bug ID CSCuu52976. |
2015-07-18 |
4.3 |
CVE-2015-4458 CISCO |
ghisler — total_commander |
The FileInfo plugin before 2.22 for Ghisler Total Commander allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via (1) a large Size value in the Archive Member Header of a COFF Archive Library file, (2) a large Number Of Symbols value in the 1st Linker Member of a COFF Archive Library file, (3) a large Resource Table Count value in the LE Header of a Linear Executable file, or (4) a large value in a certain Object field in a Resource Table Entry in a Linear Executable file. |
2015-07-21 |
5.0 |
CVE-2015-2869 CERT-VN MISC MISC |
google — chrome |
The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have unspecified other impact via a crafted file. |
2015-07-22 |
6.8 |
CVE-2015-1270 CONFIRM CONFIRM CONFIRM CONFIRM |
google — chrome |
PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted PDF document that triggers a large memory allocation. |
2015-07-22 |
6.8 |
CVE-2015-1271 CONFIRM CONFIRM CONFIRM |
google — chrome |
Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid JPEG2000 data in a PDF document. |
2015-07-22 |
6.8 |
CVE-2015-1273 CONFIRM CONFIRM CONFIRM |
google — chrome |
Google Chrome before 44.0.2403.89 does not ensure that the auto-open list omits all dangerous file types, which makes it easier for remote attackers to execute arbitrary code by providing a crafted file and leveraging a user’s previous “Always open files of this type” choice, related to download_commands.cc and download_prefs.cc. |
2015-07-22 |
6.8 |
CVE-2015-1274 CONFIRM CONFIRM CONFIRM |
google — chrome |
Cross-site scripting (XSS) vulnerability in org/chromium/chrome/browser/UrlUtilities.java in Google Chrome before 44.0.2403.89 on Android allows remote attackers to inject arbitrary web script or HTML via a crafted intent: URL, as demonstrated by a trailing alert(document.cookie);// substring, aka “Universal XSS (UXSS).” |
2015-07-22 |
4.3 |
CVE-2015-1275 CONFIRM CONFIRM CONFIRM |
google — chrome |
content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document’s modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted document, as demonstrated by the alert_dialog.pdf document. |
2015-07-22 |
4.3 |
CVE-2015-1278 CONFIRM CONFIRM CONFIRM CONFIRM |
google — chrome |
core/loader/ImageLoader.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly determine the V8 context of a microtask, which allows remote attackers to bypass Content Security Policy (CSP) restrictions by providing an image from an unintended source. |
2015-07-22 |
4.3 |
CVE-2015-1281 CONFIRM CONFIRM CONFIRM |
google — chrome |
Multiple use-after-free vulnerabilities in fpdfsdk/src/javascript/Document.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, related to the (1) Document::delay and (2) Document::DoFieldDelay functions. |
2015-07-22 |
6.8 |
CVE-2015-1282 CONFIRM CONFIRM CONFIRM |
google — chrome |
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to CVE-2015-2716. |
2015-07-22 |
6.8 |
CVE-2015-1283 CONFIRM CONFIRM CONFIRM |
google — chrome |
The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which makes it easier for remote attackers to obtain sensitive information via an unspecified linear-time attack. |
2015-07-22 |
5.0 |
CVE-2015-1285 CONFIRM CONFIRM CONFIRM |
google — chrome |
Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/v8_context_native_handler.cc in Google Chrome before 44.0.2403.89 allows remote attackers to inject arbitrary web script or HTML by leveraging the lack of a certain V8 context restriction, aka a Blink “Universal XSS (UXSS).” |
2015-07-22 |
4.3 |
CVE-2015-1286 CONFIRM CONFIRM CONFIRM CONFIRM |
google — chrome |
Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to core/fetch/CSSStyleSheetResource.cpp. |
2015-07-22 |
4.3 |
CVE-2015-1287 CONFIRM CONFIRM CONFIRM |
google — chrome |
The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorrect spelling suggestions or possibly have unspecified other impact via a crafted file, a related issue to CVE-2015-1263. |
2015-07-22 |
6.8 |
CVE-2015-1288 CONFIRM CONFIRM CONFIRM |
google — chrome |
The regular-expression implementation in Google V8, as used in Google Chrome before 44.0.2403.89, mishandles interrupts, which allows remote attackers to cause a denial of service (application crash) via crafted JavaScript code, as demonstrated by an error in garbage collection during allocation of a stack-overflow exception message. |
2015-07-22 |
5.0 |
CVE-2015-5605 CONFIRM CONFIRM CONFIRM CONFIRM |
hp — system_management_homepage |
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 7.5.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. |
2015-07-21 |
6.0 |
CVE-2015-2134 HP |
ibm — db2 |
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read arbitrary text files via a crafted XML/XSLT function in a SELECT statement. |
2015-07-19 |
4.0 |
CVE-2014-8910 CONFIRM AIXAPAR AIXAPAR AIXAPAR AIXAPAR |
ibm — db2 |
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by leveraging an unspecified scalar function in a SQL statement. |
2015-07-19 |
6.8 |
CVE-2015-0157 CONFIRM AIXAPAR AIXAPAR AIXAPAR AIXAPAR |
ibm — db2 |
IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to read certain administrative files via crafted use of an automated-maintenance policy stored procedure. |
2015-07-19 |
4.0 |
CVE-2015-1883 CONFIRM AIXAPAR AIXAPAR AIXAPAR AIXAPAR |
ibm — business_process_manager |
The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows remote authenticated users to bypass intended access restrictions on task-variable value changes via unspecified vectors. |
2015-07-21 |
4.0 |
CVE-2015-1905 CONFIRM AIXAPAR |
ibm — infosphere_master_data_management |
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message. |
2015-07-19 |
4.0 |
CVE-2015-1982 CONFIRM |
ibm — infosphere_master_data_management |
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to bypass intended access restrictions and read arbitrary profiles via unspecified vectors, as demonstrated by discovering usernames for use in brute-force attacks. |
2015-07-19 |
4.0 |
CVE-2015-1984 CONFIRM |
kaseya — virtual_system_administrator |
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote authenticated users to read arbitrary files via a crafted HTTP request. |
2015-07-20 |
4.0 |
CVE-2015-2862 CERT-VN |
kaseya — virtual_system_administrator |
Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1 before 9.1.0.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. |
2015-07-20 |
4.3 |
CVE-2015-2863 CERT-VN |
microsoft — malicious_software_removal_tool |
Race condition in Microsoft Malicious Software Removal Tool (MSRT) before 5.26 allows local users to gain privileges via a crafted DLL, aka “MSRT Race Condition Vulnerability.” |
2015-07-20 |
6.9 |
CVE-2015-2418 CONFIRM |
netiq — security_solutions_for_iseries |
Multiple stack-based buffer overflows in the SafeShellExecute method in the NetIQExecObject.NetIQExec.1 ActiveX control in NetIQExec.dll in NetIQ Security Solutions for iSeries 8.1 allow remote attackers to execute arbitrary code via long arguments, aka ZDI-CAN-2699. |
2015-07-18 |
6.8 |
CVE-2015-0795 CONFIRM MISC |
novell — groupwise |
Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014 before Support Pack 2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2015-07-22 |
4.3 |
CVE-2014-0611 CONFIRM CONFIRM CONFIRM CONFIRM CONFIRM CONFIRM CONFIRM |
seeds — acmailer |
Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string. |
2015-07-19 |
5.5 |
CVE-2015-2971 CONFIRM JVNDB JVN |
solarwinds — n-able_n-central |
The RSM (aka RSMWinService) service in SolarWinds N-Able N-Central before 9.5.1.4514 uses the same password decryption key across different customers’ installations, which makes it easier for remote authenticated users to obtain the cleartext domain-administrator password by locating the encrypted password within HTML source code and then leveraging knowledge of this key from another installation. |
2015-07-21 |
4.0 |
CVE-2015-5610 CERT-VN |
wireshark — wireshark |
The dissect_wccp2r1_address_table_info function in epan/dissectors/packet-wccp.c in the WCCP dissector in Wireshark 1.12.x before 1.12.6 does not properly determine whether enough memory is available for storing IP address strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. |
2015-07-21 |
5.0 |
CVE-2015-4651 CONFIRM CONFIRM CONFIRM |
wireshark — wireshark |
epan/dissectors/packet-gsm_a_dtap.c in the GSM DTAP dissector in Wireshark 1.12.x before 1.12.6 does not properly validate digit characters, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the de_emerg_num_list and de_bcd_num functions. |
2015-07-21 |
4.3 |
CVE-2015-4652 CONFIRM CONFIRM CONFIRM |