apache — subversion |
The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evaluated revision numbers. |
2015-04-08 |
5.0 |
CVE-2015-0248 MANDRIVA CONFIRM |
apache — subversion |
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences. |
2015-04-08 |
4.0 |
CVE-2015-0251 MANDRIVA CONFIRM |
apache — flex |
Cross-site scripting (XSS) vulnerability in asdoc/templates/index.html in Apache Flex before 4.14.1 allows remote attackers to inject arbitrary web script or HTML by providing a crafted URI to JavaScript code generated by the asdoc component. |
2015-04-07 |
4.3 |
CVE-2015-1773 BUGTRAQ |
apple — iphone_os |
CFURL in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly validate URLs, which allows remote attackers to execute arbitrary code via a crafted web site. |
2015-04-10 |
6.8 |
CVE-2015-1088 CONFIRM CONFIRM APPLE APPLE |
apple — iphone_os |
CFNetwork in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle cookies during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a crafted web site. |
2015-04-10 |
5.0 |
CVE-2015-1089 CONFIRM CONFIRM APPLE APPLE |
apple — iphone_os |
CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing action, which allows attackers to obtain sensitive information by reading a history file. |
2015-04-10 |
5.0 |
CVE-2015-1090 CONFIRM APPLE |
apple — iphone_os |
The CFNetwork Session component in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle request headers during processing of redirects in HTTP responses, which allows remote attackers to bypass the Same Origin Policy via a crafted web site. |
2015-04-10 |
4.3 |
CVE-2015-1091 CONFIRM CONFIRM APPLE APPLE |
apple — apple_tv |
NSXMLParser in Foundation in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. |
2015-04-10 |
5.0 |
CVE-2015-1092 CONFIRM CONFIRM APPLE APPLE |
apple — iphone_os |
FontParser in Apple iOS before 8.3 and Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file. |
2015-04-10 |
6.8 |
CVE-2015-1093 CONFIRM CONFIRM APPLE APPLE |
apple — iphone_os |
iWork in Apple iOS before 8.3 and Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted iWork file. |
2015-04-10 |
6.8 |
CVE-2015-1098 CONFIRM CONFIRM APPLE APPLE |
apple — apple_tv |
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly determine whether an IPv6 packet had a local origin, which allows remote attackers to bypass an intended network-filtering protection mechanism via a crafted packet. |
2015-04-10 |
5.0 |
CVE-2015-1104 CONFIRM CONFIRM CONFIRM APPLE APPLE APPLE |
apple — apple_tv |
The TCP implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly implement the Urgent (aka out-of-band data) mechanism, which allows remote attackers to cause a denial of service via crafted packets. |
2015-04-10 |
5.0 |
CVE-2015-1105 CONFIRM CONFIRM CONFIRM APPLE APPLE APPLE |
apple — apple_tv |
The Podcasts component in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to discover unique identifiers by reading asset-download request data. |
2015-04-10 |
5.0 |
CVE-2015-1110 CONFIRM CONFIRM APPLE APPLE |
apple — iphone_os |
Safari in Apple iOS before 8.3 does not delete Recently Closed Tabs data in response to a history-clearing action, which allows attackers to obtain sensitive information by reading a history file. |
2015-04-10 |
5.0 |
CVE-2015-1111 CONFIRM APPLE |
apple — safari |
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, as used on iOS before 8.3 and other platforms, does not properly delete browsing-history data from the history.plist file, which allows attackers to obtain sensitive information by reading this file. |
2015-04-10 |
5.0 |
CVE-2015-1112 CONFIRM CONFIRM APPLE APPLE |
apple — apple_tv |
libnetcore in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service (memory corruption and application crash) via a crafted configuration profile. |
2015-04-10 |
5.0 |
CVE-2015-1118 CONFIRM CONFIRM CONFIRM APPLE APPLE APPLE |
apple — apple_tv |
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-SA-2015-04-08-4. |
2015-04-10 |
6.8 |
CVE-2015-1119 CONFIRM CONFIRM CONFIRM APPLE APPLE APPLE |
apple — apple_tv |
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-SA-2015-04-08-4. |
2015-04-10 |
6.8 |
CVE-2015-1120 CONFIRM CONFIRM CONFIRM APPLE APPLE APPLE |
apple — apple_tv |
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-SA-2015-04-08-4. |
2015-04-10 |
6.8 |
CVE-2015-1121 CONFIRM CONFIRM CONFIRM APPLE APPLE APPLE |
apple — apple_tv |
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-SA-2015-04-08-4. |
2015-04-10 |
6.8 |
CVE-2015-1122 CONFIRM CONFIRM CONFIRM APPLE APPLE APPLE |
apple — apple_tv |
WebKit, as used in Apple iOS before 8.3 and Apple TV before 7.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-3 and APPLE-SA-2015-04-08-4. |
2015-04-10 |
6.8 |
CVE-2015-1123 CONFIRM CONFIRM APPLE APPLE |
apple — apple_tv |
WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-SA-2015-04-08-4. |
2015-04-10 |
6.8 |
CVE-2015-1124 CONFIRM CONFIRM CONFIRM APPLE APPLE APPLE |
apple — iphone_os |
The touch-events implementation in WebKit in Apple iOS before 8.3 allows remote attackers to trigger an association between a tap and an unintended web resource via a crafted web site. |
2015-04-10 |
4.3 |
CVE-2015-1125 CONFIRM APPLE |
apple — safari |
WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not properly handle the userinfo field in FTP URLs, which allows remote attackers to trigger incorrect resource access via unspecified vectors. |
2015-04-10 |
4.3 |
CVE-2015-1126 CONFIRM CONFIRM APPLE APPLE |
apple — safari |
The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 allows attackers to obtain sensitive browsing-history information via vectors involving push-notification requests. |
2015-04-10 |
5.0 |
CVE-2015-1128 CONFIRM APPLE |
apple — safari |
Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 does not properly select X.509 client certificates, which makes it easier for remote attackers to track users via a crafted web site. |
2015-04-10 |
4.3 |
CVE-2015-1129 CONFIRM APPLE |
apple — mac_os_x |
Use-after-free vulnerability in CoreAnimation in Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code by leveraging improper use of a mutex. |
2015-04-10 |
6.8 |
CVE-2015-1136 CONFIRM APPLE |
apple — mac_os_x |
Hypervisor in Apple OS X before 10.10.3 allows local users to cause a denial of service via unspecified vectors. |
2015-04-10 |
4.9 |
CVE-2015-1138 CONFIRM APPLE |
apple — mac_os_x |
ImageIO in Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .sgi file. |
2015-04-10 |
6.8 |
CVE-2015-1139 CONFIRM APPLE |
apple — mac_os_x |
The mach_vm_read functionality in the kernel in Apple OS X before 10.10.3 allows local users to cause a denial of service (system crash) via unspecified vectors. |
2015-04-10 |
4.9 |
CVE-2015-1141 CONFIRM APPLE |
apple — mac_os_x |
Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitive information by sniffing the network. |
2015-04-10 |
5.0 |
CVE-2015-1147 CONFIRM APPLE |
apple — mac_os_x |
Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-dependent attackers to obtain sensitive information by reading this file. |
2015-04-10 |
5.0 |
CVE-2015-1148 CONFIRM APPLE |
arj_software — arj_archiver |
Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive. |
2015-04-08 |
5.8 |
CVE-2015-0556 CONFIRM MLIST MLIST DEBIAN |
arj_software — arj_archiver |
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive. |
2015-04-08 |
5.8 |
CVE-2015-0557 CONFIRM MLIST MLIST DEBIAN |
bblog_project — bblog |
Cross-site request forgery (CSRF) vulnerability in bBlog allows remote attackers to hijack the authentication of arbitrary users. |
2015-04-07 |
6.8 |
CVE-2015-0905 MISC JVNDB JVN |
cisco — unified_communications_domain_manager |
Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a “deprecated page,” aka Bug ID CSCup90168. |
2015-04-03 |
6.5 |
CVE-2015-0682 SECTRACK CISCO |
cisco — unified_communications_domain_manager |
Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to obtain sensitive information via a file-inclusion attack, aka Bug ID CSCup94744. |
2015-04-03 |
4.0 |
CVE-2015-0683 SECTRACK CISCO |
cisco — unified_communications_domain_manager |
SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuq52515. |
2015-04-03 |
6.5 |
CVE-2015-0684 SECTRACK CISCO |
cisco — wireless_lan_controller_software |
Cross-site scripting (XSS) vulnerability in the HTML help system on Cisco Wireless LAN Controller (WLC) devices before 8.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCun95178. |
2015-04-06 |
4.3 |
CVE-2015-0690 SECTRACK CISCO |
emc — powerpath_virtual_appliance |
EMC PowerPath Virtual Appliance (aka vApp) before 2.0 has default passwords for the (1) emcupdate and (2) svcuser accounts, which makes it easier for remote attackers to obtain potentially sensitive information via a login session. |
2015-04-04 |
5.0 |
CVE-2015-0529 BUGTRAQ MISC |
ericsson — drutt_mobile_service_delivery_platform |
Multiple cross-site scripting (XSS) vulnerabilities in the Report Viewer in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allow remote attackers to inject arbitrary web script or HTML via the (1) portal, (2) fromDate, (3) toDate, (4) fromTime, (5) toTime, (6) kword, (7) uname, (8) pname, (9) sname, (10) atype, or (11) atitle parameter to top-links.jsp; (12) portal or (13) uid parameter to (a) page-summary.jsp or (b) service-summary.jsp; (14) portal, (15) fromDate, (16) toDate, (17) fromTime, (18) toTime, (19) sortDirection, (20) kword, (21) uname, (22) pname, (23) sname, (24) file, (25) atype, or (26) atitle parameter to (a) top-useragent-devices.jsp or (b) top-interest-areas.jsp; (27) fromDate, (28) toDate, (29) fromTime, (30) toTime, (31) sortDirection, (32) kword, (33) uname, (34) pname, (35) sname, (36) file, (37) atype, or (38) atitle parameter to top-message-services.jsp; (39) portal, (40) fromDate, (41) toDate, (42) fromTime, (43) toTime, (44) orderBy, (45) sortDirection, (46) kword, (47) uname, (48) pname, (49) sname, (50) file, (51) atype, or (52) atitle parameter to (a) user-statistics.jsp, (b) top-web-pages.jsp, (c) top-devices.jsp, (d) top-pages.jsp, (e) session-summary.jsp, (f) top-providers.jsp, (g) top-modules.jsp, or (h) top-services.jsp; (53) fromDate, (54) toDate, (55) fromTime, (56) toTime, (57) orderBy, (58) sortDirection, (59) uid, (60) uid2, (61) kword, (62) uname, (63) pname, (64) sname, (65) file, (66) atype, or (67) atitle parameter to message-shortcode-summary.jsp; (68) fromDate, (69) toDate, (70) fromTime, (71) toTime, (72) orderBy, (73) sortDirection, (74) uid, (75) kword, (76) uname, (77) pname, (78) sname, (79) file, (80) atype, or (81) atitle parameter to (a) message-providers-summary.jsp or (b) message-services-summary.jsp; (82) kword, (83) uname, (84) pname, (85) sname, (86) file, (87) atype, or (88) atitle parameter to license-summary.jsp; (89) portal, (90) fromDate, (91) toDate, (92) fromTime, (93) toTime, (94) orderBy, (95) sortDirection, (96) uid, (97) uid2, (98) kword, (99) uname, (100) pname, (101) sname, (102) file, (103) atype, or (104) atitle parameter to useragent-device-summary.jsp; (105) fromDate, (106) toDate, (107) fromTime, (108) toTime, (109) orderBy, (110) sortDirection, (111) kword, (112) uname, (113) pname, (114) sname, (115) file, (116) atype, or (117) atitle parameter to (a) top-message-providers.jsp, (b) top-message-devices.jsp, (c) top-message-assets.jsp, (d) top-message-downloads.jsp, or (e) top-message-shortcode.jsp; (118) fromDate, (119) toDate, (120) fromTime, (121) toTime, (122) kword, (123) uname, (124) pname, (125) sname, (126) file, (127) atype, or (128) atitle parameter to request-summary.jsp; (129) portal parameter to link-summary-select.jsp, (130) provider-summary-select.jsp, or (131) module-summary-select.jsp; (132) portal, (133) uid, (134) kword, (135) uname, (136) pname, (137) sname, (138) file, (139) atype, or (140) atitle parameter to link-summary.jsp; (141) portal, (142) fromDate, (143) toDate, (144) fromTime, (145) toTime, (146) orderBy, (147) sortDirection, (148) uid, (149) kword, (150) uname, (151) pname, (152) sname, (153) file, (154) atype, or (155) atitle parameter to (a) provider-summary.jsp or (b) module-summary.jsp in reports/pages/. |
2015-04-06 |
4.3 |
CVE-2015-2165 MISC |
ericsson — drutt_mobile_service_delivery_platform |
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI. |
2015-04-06 |
5.0 |
CVE-2015-2166 MISC |
ericsson — drutt_mobile_service_delivery_platform |
Open redirect vulnerability in the 3PI Manager in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter to jsp/start-3pi-manager.jsp. |
2015-04-06 |
5.8 |
CVE-2015-2167 MISC |
gnu — glibc |
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite memory locations beyond the stack boundary via a long line containing wide characters that are improperly handled in a wscanf call. |
2015-04-08 |
6.4 |
CVE-2015-1473 CONFIRM MLIST |
ibm — websphere_datapower_xc10_appliance_firmware |
The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obtain sensitive information or modify data, via unspecified vectors. |
2015-04-05 |
6.8 |
CVE-2015-1893 CONFIRM SECTRACK AIXAPAR |
mcafee — advanced_threat_defense |
McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to bypass intended restrictions and change or update configuration settings via crafted parameters. |
2015-04-08 |
5.5 |
CVE-2015-3028 CONFIRM |
mcafee — advanced_threat_defense |
The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 does not properly restrict access, which allows remote authenticated users to obtain sensitive information via unspecified vectors. |
2015-04-08 |
4.0 |
CVE-2015-3029 CONFIRM |
mcafee — advanced_threat_defense |
The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to obtain sensitive configuration information via unspecified vectors. |
2015-04-08 |
4.0 |
CVE-2015-3030 CONFIRM |
mozilla — firefox |
The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy. |
2015-04-08 |
5.0 |
CVE-2015-0798 CONFIRM CONFIRM |
mozilla — firefox |
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header. |
2015-04-08 |
4.3 |
CVE-2015-0799 CONFIRM CONFIRM |
ntp — ntp |
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 3.x and 4.x before 4.2.8p2 performs state-variable updates upon receiving certain invalid packets, which makes it easier for man-in-the-middle attackers to cause a denial of service (synchronization loss) by spoofing the source IP address of a peer. |
2015-04-08 |
4.3 |
CVE-2015-1799 CERT-VN CONFIRM CONFIRM |
pfsense — pfsense |
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deletefile parameter. |
2015-04-10 |
6.8 |
CVE-2015-2295 CONFIRM MISC BUGTRAQ MISC |
qualiteam — x-cart |
Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject arbitrary web script or HTML via the substring parameter. |
2015-04-04 |
4.3 |
CVE-2015-0950 CERT-VN CONFIRM |
qualiteam — x-cart |
X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2) remove request. |
2015-04-04 |
6.5 |
CVE-2015-0951 CERT-VN CONFIRM |
quassel-irc — quassel |
Quassel before 0.12-rc1 uses an incorrect data-type size when splitting a message, which allows remote attackers to cause a denial of service (crash) via a long CTCP query containing only multibyte characters. |
2015-04-10 |
5.0 |
CVE-2015-2778 CONFIRM MLIST MLIST MLIST SUSE |
redhat — docker |
The Red Hat docker package before 1.5.0-28, when using the –add-registry option, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic. NOTE: this vulnerability exists because of a CVE-2014-5277 regression. |
2015-04-06 |
4.3 |
CVE-2015-1843 CONFIRM REDHAT |
saurus — saurus_cms |
Multiple cross-site scripting (XSS) vulnerabilities in the print_language_selectbox function in classes/adminpage.inc.php in Saurus CMS Community Edition before 4.7 2015-02-04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2015-04-06 |
4.3 |
CVE-2015-0876 CONFIRM JVNDB JVN |
schneider-electric — vampset |
Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malformed disturbance-recording data in a (1) CFG or (2) DAT file. |
2015-04-03 |
4.4 |
CVE-2014-8390 MISC CONFIRM BUGTRAQ MISC |
siemens — simatic_step_7 |
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 allows man-in-the-middle attackers to obtain sensitive information or modify transmitted data via unspecified vectors. |
2015-04-05 |
6.8 |
CVE-2015-1601 CONFIRM |
siemens — wincc |
Siemens SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2 and SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2 allow man-in-the-middle attackers to cause a denial of service via crafted packets on TCP port 102. |
2015-04-08 |
4.3 |
CVE-2015-2822 CONFIRM |
siemens — wincc |
Siemens SIMATIC HMI Basic Panels 2nd Generation before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC WinCC Runtime Professional before WinCC (TIA Portal) 13 SP1 Upd2, SIMATIC HMI Basic Panels 1st Generation (WinCC TIA Portal), SIMATIC HMI Mobile Panel 277 (WinCC TIA Portal), SIMATIC HMI Multi Panels (WinCC TIA Portal), and SIMATIC WinCC 7.x before 7.3 Upd4 allow remote attackers to complete authentication by leveraging knowledge of a password hash without knowledge of the associated password. |
2015-04-08 |
6.8 |
CVE-2015-2823 CONFIRM |