| 7-zip -- p7zip |
p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive. |
2015年01月21日 |
5.8 |
CVE-2015-1038 MISC MISC XF BID MLIST |
| apache -- xml_security |
Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document. |
2015年01月21日 |
5.0 |
CVE-2014-8152 XF SECTRACK BID MLIST |
| b2evolution -- b2evolution |
Cross-site scripting (XSS) vulnerability in the filemanager in b2evolution before 5.2.1 allows remote attackers to inject arbitrary web script or HTML via the fm_filter parameter to blogs/admin.php. |
2015年01月16日 |
4.3 |
CVE-2014-9599 CONFIRM XF BID MISC MISC FULLDISC MISC |
| brother -- mfc-j4410dw |
Cross-site scripting (XSS) vulnerability in Brother MFC-J4410DW printer with firmware before L allows remote attackers to inject arbitrary web script or HTML via the url parameter to general/status.html and possibly other pages. |
2015年01月16日 |
4.3 |
CVE-2015-1056 XF BID BUGTRAQ MISC |
| cagintranetworks -- getsimple_cms |
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter. |
2015年01月20日 |
5.0 |
CVE-2014-8790 CONFIRM FULLDISC MISC MISC CONFIRM |
| cisco -- unified_communications_manager |
Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authenticated users to read arbitrary files via a full pathname in an API command, aka Bug ID CSCur49414. |
2015年01月22日 |
6.8 |
CVE-2014-8008 |
| cisco -- webex_meeting_center |
Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providing crafted parameters during a meeting-join action, aka Bug ID CSCuo34165. |
2015年01月17日 |
5.0 |
CVE-2015-0590 |
| clorius_controls_a/s -- java_web_client |
The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equivalent traffic. |
2015年01月16日 |
5.0 |
CVE-2014-9199 |
| croogo -- croogo |
Cross-site scripting (XSS) vulnerability in the administrative backend in Croogo before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the path parameter to admin/file_manager/file_manager/editfile. |
2015年01月16日 |
4.3 |
CVE-2015-1053 CONFIRM XF BID MISC MISC FULLDISC MISC |
| debian -- dpkg |
Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name. |
2015年01月20日 |
6.8 |
CVE-2014-8625 CONFIRM CONFIRM XF MLIST MLIST MLIST |
| djangoproject -- django |
Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) character in an HTTP header, as demonstrated by an X-Auth_User header. |
2015年01月16日 |
5.0 |
CVE-2015-0219 SECUNIA SECUNIA |
| djangoproject -- django |
The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL, related to redirect URLs, as demonstrated by a "\njavascript:" URL. |
2015年01月16日 |
4.3 |
CVE-2015-0220 UBUNTU SECUNIA SECUNIA |
| djangoproject -- django |
The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file. |
2015年01月16日 |
5.0 |
CVE-2015-0221 SECUNIA SECUNIA |
| djangoproject -- django |
ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries. |
2015年01月16日 |
5.0 |
CVE-2015-0222 SECUNIA SECUNIA |
| e107 -- e107 |
Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary web script or HTML via the "Real Name" value. |
2015年01月16日 |
4.3 |
CVE-2015-1057 XF EXPLOIT-DB OSVDB |
| emc -- vipr_srm |
EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access to conduct a decryption attack. |
2015年01月21日 |
5.0 |
CVE-2015-0514 BUGTRAQ |
| emc -- vipr_srm |
Unrestricted file upload vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to execute arbitrary code by uploading and then accessing an executable file. |
2015年01月21日 |
6.5 |
CVE-2015-0515 BUGTRAQ |
| emc -- vipr_srm |
Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL. |
2015年01月21日 |
4.0 |
CVE-2015-0516 BUGTRAQ |
| file_project -- file |
The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes. |
2015年01月21日 |
5.0 |
CVE-2014-9620 CONFIRM MLIST DEBIAN MLIST |
| file_project -- file |
The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string. |
2015年01月21日 |
5.0 |
CVE-2014-9621 CONFIRM MLIST MLIST |
| ge -- intelligent_platforms_proficy_hmi/scada_cimplicity |
The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file. |
2015年01月16日 |
6.9 |
CVE-2014-2355 |
| ge -- multilink_ml1200 |
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the same RSA private key across different customers' installations, which makes it easier for remote attackers to obtain the cleartext content of network traffic by reading this key from a firmware image and then sniffing the network. |
2015年01月16日 |
5.0 |
CVE-2014-5419 |
| gentoo -- xdg-utils |
Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open. |
2015年01月21日 |
6.8 |
CVE-2014-9622 CONFIRM CONFIRM MLIST DEBIAN SECUNIA FULLDISC |
| getsentry -- raven-ruby |
The numtok function in lib/raven/okjson.rb in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a large exponent value in a scientific number. |
2015年01月20日 |
5.0 |
CVE-2014-9490 CONFIRM CONFIRM XF MLIST |
| getusedtoit -- wp_slimstat |
Cross-site scripting (XSS) vulnerability in the Save Filters functionality in the WP Slimstat plugin before 3.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fs[resource] parameter in the wp-slim-view-2 page to wp-admin/admin.php. |
2015年01月21日 |
4.3 |
CVE-2015-1204 MISC CONFIRM SECUNIA |
| gnu -- patch |
GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file. |
2015年01月21日 |
4.3 |
CVE-2015-1196 CONFIRM CONFIRM XF BID MLIST CONFIRM |
| google -- chrome |
Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering duplicate BLOB references, related to content/browser/indexed_db/indexed_db_callbacks.cc and content/browser/indexed_db/indexed_db_dispatcher_host.cc. |
2015年01月22日 |
5.0 |
CVE-2014-7924 CONFIRM CONFIRM |
| google -- chrome |
Use-after-free vulnerability in the ZoomBubbleView::Close function in browser/ui/views/location_bar/zoom_bubble_view.cc in the Views implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document that triggers improper maintenance of a zoom bubble. |
2015年01月22日 |
6.8 |
CVE-2014-7936 CONFIRM CONFIRM |
| google -- chrome |
Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted _javascript_ code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header. |
2015年01月22日 |
4.3 |
CVE-2014-7939 |
| google -- chrome |
The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted X11 data. |
2015年01月22日 |
5.0 |
CVE-2014-7941 |
| google -- chrome |
Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. |
2015年01月22日 |
5.0 |
CVE-2014-7943 CONFIRM |
| google -- chrome |
The sycc422_to_rgb function in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 40.0.2214.91, does not properly handle odd values of image width, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document. |
2015年01月22日 |
5.0 |
CVE-2014-7944 |
| google -- chrome |
OpenJPEG before r2908, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, and t2.c. |
2015年01月22日 |
5.0 |
CVE-2014-7945 |
| google -- chrome |
The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as used in Google Chrome before 40.0.2214.91, skips captions during table layout in certain situations, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors related to the Fonts implementation. |
2015年01月22日 |
5.0 |
CVE-2014-7946 CONFIRM |
| google -- chrome |
OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2.c, and tcd.c. |
2015年01月22日 |
5.0 |
CVE-2014-7947 |
| google -- chrome |
The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_update_job.cc in Google Chrome before 40.0.2214.91 proceeds with AppCache caching for SSL sessions even if there is an X.509 certificate error, which allows man-in-the-middle attackers to spoof HTML5 application content via a crafted certificate. |
2015年01月22日 |
4.3 |
CVE-2014-7948 |
| ibm -- sas_connectivity_module_firmware |
IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to obtain blade and storage-pool access via a TELNET session. |
2015年01月17日 |
5.0 |
CVE-2014-3019 XF |
| ibm -- api_management |
IBM API Management 3.0 before 3.0.4.0 IF1 allows remote attackers to obtain sensitive analytics information in an encrypted form via unspecified vectors. |
2015年01月21日 |
5.0 |
CVE-2014-6172 XF AIXAPAR |
| ibm -- security_network_protection_xgs_firmware |
IBM Security Network Protection 5.1.x and 5.2.x before 5.2.0.0 FP5 and 5.3.x before 5.3.0.0 FP1 allows remote attackers to conduct clickjacking attacks via unspecified vectors. |
2015年01月17日 |
4.3 |
CVE-2014-6197 XF |
| illumos -- illumos |
The devzvol_readdir function in illumos does not check the return value of a strchr call, which allows remote attackers to cause a denial of service (NULL pointer dereference and panic) via unspecified vectors. |
2015年01月20日 |
5.0 |
CVE-2014-9491 CONFIRM CONFIRM XF MLIST |
| insanevisions -- adaptcms |
Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Category][title] parameter to admin/categories/add, (2) data[Field][title] parameter to admin/fields/ajax_fields/, (3) name property in a basicInfo JSON object to admin/tools/create_theme, (4) data[Link][link_title] parameter to admin/links/links/add, or (5) data[ForumTopic][subject] parameter to forums/off-topic/new. |
2015年01月16日 |
4.3 |
CVE-2015-1058 XF MISC EXPLOIT-DB MISC OSVDB OSVDB OSVDB OSVDB OSVDB |
| insanevisions -- adaptcms |
Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in /app/webroot/uploads. |
2015年01月16日 |
6.5 |
CVE-2015-1059 MISC XF EXPLOIT-DB MISC OSVDB |
| insanevisions -- adaptcms |
Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header. |
2015年01月16日 |
5.8 |
CVE-2015-1060 XF MISC EXPLOIT-DB MISC OSVDB |
| juniper -- junos |
The stateless firewall in Juniper Junos 13.3R3, 14.1R1, and 14.1R2, when using Trio-based PFE modules, does not properly match ports, which might allow remote attackers to bypass firewall rule. |
2015年01月16日 |
5.0 |
CVE-2014-6383 SECTRACK BID |
| juniper -- junos |
Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D15, 12.3 before 12.3R9, 13.1 before 13.1R4-S3, 13.2 before 13.2R6, 13.3 before 13.3R5, 14.1 before 14.1R3, and 14.2 before 14.2R1 does not properly handle double quotes in authorization attributes in the TACACS+ configuration, which allows local users to bypass the security policy and execute commands via unspecified vectors. |
2015年01月16日 |
6.9 |
CVE-2014-6384 SECTRACK BID |
| juniper -- junos |
Juniper Junos 11.4 before 11.4R13, 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, 12.2 before 12.2R9, 12.3R7 before 12.3R7-S1, 12.3 before 12.3R8, 13.1 before 13.1R5, 13.2 before 13.2R6, 13.3 before 13.3R4, 14.1 before 14.1R2, and 14.2 before 14.2R1 allows remote attackers to cause a denial of service (kernel crash and restart) via a crafted fragmented OSPFv3 packet with an IPsec Authentication Header (AH). |
2015年01月16日 |
6.1 |
CVE-2014-6385 BID |
| kde -- kde_applications |
kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack. |
2015年01月18日 |
5.0 |
CVE-2013-7252 CONFIRM BID MLIST MLIST MISC |
| kgb_project -- kgb |
Absolute path traversal vulnerability in kgb 1.0b4 allows remote attackers to write to arbitrary files via a full pathname in a crafted archive. |
2015年01月21日 |
5.0 |
CVE-2015-1192 MISC BID MLIST SECUNIA |
| kiwix -- kiwix |
Cross-site scripting (XSS) vulnerability in Kiwix before 0.9.1, when using kiwix-serve, allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to /search. |
2015年01月21日 |
4.3 |
CVE-2015-1032 BUGTRAQ CONFIRM MISC MISC |
| libtiff -- libtiff |
Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-bounds read. |
2015年01月20日 |
5.0 |
CVE-2014-9330 SECTRACK FULLDISC CONFIRM |
| mediawiki -- mediawiki |
MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAXdomains via a domain that has a partial match to an allowed origin, as demonstrated by "http://en.wikipedia.org.evilsite.example/." |
2015年01月16日 |
5.0 |
CVE-2014-9476 CONFIRM MLIST MLIST |
| mediawiki -- mediawiki |
Multiple cross-site scripting (XSS) vulnerabilities in the Listings extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) url parameter. |
2015年01月16日 |
4.3 |
CVE-2014-9477 CONFIRM MLIST MLIST |
| mediawiki -- mediawiki |
Cross-site scripting (XSS) vulnerability in the preview in the TemplateSandbox extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via the text parameter to Special:TemplateSandbox. |
2015年01月16日 |
4.3 |
CVE-2014-9479 CONFIRM MLIST MLIST |
| mediawiki -- mediawiki |
Cross-site scripting (XSS) vulnerability in the Hovercards extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors related to text extracts. |
2015年01月16日 |
4.3 |
CVE-2014-9480 CONFIRM MLIST MLIST |
| openstack -- image_registry_and_delivery_service_(glance) |
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014年1月4日 and 2014.2.x before 2014年2月2日 allows remote authenticated users to read or delete arbitrary files via a full pathname in a filesystem: URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9493. |
2015年01月21日 |
6.5 |
CVE-2015-1195 CONFIRM MLIST MLIST SECUNIA MLIST |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect availability via unknown vectors related to Web Listener, a different vulnerability than CVE-2013-0338, CVE-2013-2877, and CVE-2015-0386. |
2015年01月21日 |
4.3 |
CVE-2014-0191 |
| oracle -- oracle_and_sun_systems_product_suite |
Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to System management. |
2015年01月21日 |
6.5 |
CVE-2014-6480 |
| oracle -- database_server |
Unspecified vulnerability in the PL/SQL component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality via unknown vectors. |
2015年01月21日 |
4.0 |
CVE-2014-6514 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle Directory Server Enterprise Edition component in Oracle Fusion Middleware 7.0 allows remote attackers to affect integrity via unknown vectors related to Admin Console. |
2015年01月21日 |
4.3 |
CVE-2014-6526 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel Core - System Management component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Server Infrastructure. |
2015年01月21日 |
4.0 |
CVE-2014-6528 |
| oracle -- database_server |
Unspecified vulnerability in the Recovery component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenticated users to affect confidentiality via vectors related to DBMS_IR. |
2015年01月21日 |
6.3 |
CVE-2014-6541 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle SOA Suite component in Oracle Fusion Middleware 11.1.1.7 allows local users to affect confidentiality, integrity, and availability via vectors related to B2B Engine. |
2015年01月21日 |
4.6 |
CVE-2014-6548 |
| oracle -- e-business_suite |
Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to AD_DDL. |
2015年01月21日 |
4.6 |
CVE-2014-6556 |
| oracle -- peoplesoft_products |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 allows remote authenticated users to affect integrity via unknown vectors related to Portal. |
2015年01月21日 |
4.0 |
CVE-2014-6566 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality via vectors related to CIE Related Components. |
2015年01月21日 |
5.0 |
CVE-2014-6569 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Web Listener, a different vulnerability than CVE-2011-1944. |
2015年01月21日 |
6.8 |
CVE-2014-6571 |
| oracle -- e-business_suite |
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors related to List of Values. |
2015年01月21日 |
6.4 |
CVE-2014-6572 |
| oracle -- enterprise_manager_grid_control |
Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 11.1.3 and 12.1.4 allows remote attackers to affect integrity via unknown vectors related to User Interface Framework. |
2015年01月21日 |
4.3 |
CVE-2014-6573 |
| oracle -- supply_chain_products_suite |
Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 6.1.0.3 allows remote attackers to affect integrity via unknown vectors related to Testing Protocol Library. |
2015年01月21日 |
4.3 |
CVE-2014-6574 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle Adaptive Access Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to OAM Integration. |
2015年01月21日 |
5.5 |
CVE-2014-6576 |
| oracle -- database_server |
Unspecified vulnerability in the XML Developer's Kit for C component in Oracle Database Server 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the original researcher's claim that this is an XML external entity (XXE) vulnerability in the XML parser, which allows attackers to conduct internal port scanning, perform SSRF attacks, or cause a denial of service via a crafted (1) http: or (2) ftp: URI. |
2015年01月21日 |
6.8 |
CVE-2014-6577 MISC |
| oracle -- database_server |
Unspecified vulnerability in the Workspace Manager component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SDO_TOPO and WMSYS.LT. |
2015年01月21日 |
6.5 |
CVE-2014-6578 |
| oracle -- peoplesoft_products |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote authenticated users to affect confidentiality via unknown vectors related to Integration Broker. |
2015年01月21日 |
4.0 |
CVE-2014-6579 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.7 and 11.1.2.2 allows remote attackers to affect integrity via unknown vectors. |
2015年01月21日 |
4.3 |
CVE-2014-6580 |
| oracle -- e-business_suite |
Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Extract/Load Programs. |
2015年01月21日 |
6.4 |
CVE-2014-6581 |
| oracle -- e-business_suite |
Unspecified vulnerability in the Oracle HCM Configuration Workbench component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via unknown vectors related to Rapid Implementation. |
2015年01月21日 |
5.0 |
CVE-2014-6582 |
| oracle -- e-business_suite |
Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, and 12.1.3. allows remote attackers to affect confidentiality and integrity via unknown vectors related to Audience. |
2015年01月21日 |
6.4 |
CVE-2014-6583 |
| oracle -- integrated_lights_out_manager_firmware |
Unspecified vulnerability in the Integrated Lights Out Manager (ILOM) component in Oracle Sun Systems Products Suite ILOM before 3.2.4 allows remote authenticated users to affect confidentiality via unknown vectors related to Backup Restore. |
2015年01月21日 |
4.0 |
CVE-2014-6584 |
| oracle -- peoplesoft_products |
Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Time and Labor. |
2015年01月21日 |
5.5 |
CVE-2014-6586 |
| oracle -- jdk |
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. |
2015年01月21日 |
4.3 |
CVE-2014-6587 |
| oracle -- jdk |
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. |
2015年01月21日 |
4.0 |
CVE-2014-6593 |
| oracle -- ilearning |
Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect confidentiality via unknown vectors related to Learner Pages. |
2015年01月21日 |
4.3 |
CVE-2014-6594 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to Portal Framework. |
2015年01月21日 |
4.3 |
CVE-2014-6596 |
| oracle -- peoplesoft_products |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52, 8.53, and 8.54 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology. |
2015年01月21日 |
4.0 |
CVE-2014-6597 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7 allows remote attackers to affect confidentiality via unknown vectors related to BI Publisher Security. |
2015年01月21日 |
5.0 |
CVE-2015-0362 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel Core EAI component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect availability via unknown vectors related to Integration Business Services. |
2015年01月21日 |
4.0 |
CVE-2015-0363 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel Core - Server Infrastructure component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Security. |
2015年01月21日 |
4.3 |
CVE-2015-0365 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel Core - EAI component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Java Integration. |
2015年01月21日 |
5.0 |
CVE-2015-0366 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to affect integrity via vectors related to SSO Engine. |
2015年01月21日 |
5.0 |
CVE-2015-0367 |
| oracle -- supply_chain_products_suite |
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, 6.3.4, and 6.3.5 allows remote attackers to affect availability via unknown vectors related to Security. |
2015年01月21日 |
5.0 |
CVE-2015-0368 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to AX/HI Web UI. |
2015年01月21日 |
4.3 |
CVE-2015-0369 |
| oracle -- database_server |
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect integrity and availability via unknown vectors. |
2015年01月21日 |
4.9 |
CVE-2015-0371 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality via unknown vectors. |
2015年01月21日 |
5.0 |
CVE-2015-0372 |
| oracle -- database_server |
Unspecified vulnerability in the OJVM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. |
2015年01月21日 |
6.5 |
CVE-2015-0373 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 11.1.1.8.0 allows remote attackers to affect integrity via unknown vectors related to Content Server. |
2015年01月21日 |
4.3 |
CVE-2015-0376 |
| oracle -- vm_virtualbox |
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.26, 4.0.28, 4.1.36, and 4.2.28 allows local users to affect availability via unknown vectors related to Core, a different vulnerability than CVE-2015-0418. |
2015年01月21日 |
4.4 |
CVE-2015-0377 |
| oracle -- peoplesoft_products |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 allows remote attackers to affect integrity via vectors related to PIA Core Technology. |
2015年01月21日 |
4.3 |
CVE-2015-0379 |
| oracle -- e-business_suite |
Unspecified vulnerability in the Oracle Telecommunications Billing Integrator component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via unknown vectors related to OA Based UI for Bill Summary. |
2015年01月21日 |
4.3 |
CVE-2015-0380 |
| oracle -- mysql |
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382. |
2015年01月21日 |
4.3 |
CVE-2015-0381 |
| oracle -- mysql |
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381. |
2015年01月21日 |
4.3 |
CVE-2015-0382 |
| oracle -- jdk |
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related to Hotspot. |
2015年01月21日 |
5.4 |
CVE-2015-0383 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect availability via unknown vectors related to Web Listener, a different vulnerability than CVE-2013-0338, CVE-2013-2877, and CVE-2014-0191. |
2015年01月21日 |
4.3 |
CVE-2015-0386 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel Core - Server OM Services component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via vectors related to Security - LDAP Security Adapter. |
2015年01月21日 |
4.0 |
CVE-2015-0387 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Portal Framework, a different vulnerability than CVE-2015-0417. |
2015年01月21日 |
4.0 |
CVE-2015-0388 |
| oracle -- retail_applications_xstore |
Unspecified vulnerability in the MICROS Retail component in Oracle Retail Applications Xstore: 3.2.1, 3.4.2, 3.5.0, 4.0.1, 4.5.1, 4.8.0, 5.0.3, 5.5.3, 6.0.6, and 6.5.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Xstore Point of Sale. |
2015年01月21日 |
6.8 |
CVE-2015-0390 |
| oracle -- mysql |
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to DDL. |
2015年01月21日 |
4.0 |
CVE-2015-0391 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel Core - Server BizLogic Script component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Config - Scripting. |
2015年01月21日 |
4.6 |
CVE-2015-0392 |
| oracle -- e-business_suite |
Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to DB Privileges. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the researcher's claim that the PUBLIC role is granted the INDEX privilege for the DUAL table during a "seeded install," which allows remote authenticated users to gain SYSDBA privileges and execute arbitrary code. |
2015年01月21日 |
6.0 |
CVE-2015-0393 |
| oracle -- peoplesoft_products |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote authenticated users to affect confidentiality via unknown vectors related to Report Distribution. |
2015年01月21日 |
4.0 |
CVE-2015-0394 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel Life Sciences component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Clinical Trip Report. |
2015年01月21日 |
4.0 |
CVE-2015-0398 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 10.1.3.4.2 and 11.1.1.7 allows remote authenticated users to affect confidentiality via unknown vectors related to Analytics Web General. |
2015年01月21日 |
4.0 |
CVE-2015-0399 |
| oracle -- jdk |
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries. |
2015年01月21日 |
5.0 |
CVE-2015-0400 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle Directory Server Enterprise Edition component in Oracle Fusion Middleware 7.0 and 11.1.1.7 allows remote authenticated users to affect integrity via unknown vectors related to Admin Console. |
2015年01月21日 |
4.0 |
CVE-2015-0401 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel Core - Server BizLogic Script component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via vectors related to Integration - COM. |
2015年01月21日 |
4.3 |
CVE-2015-0402 |
| oracle -- jdk |
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment. |
2015年01月21日 |
6.9 |
CVE-2015-0403 |
| oracle -- e-business_suite |
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via unknown vectors related to Error Messages. |
2015年01月21日 |
4.3 |
CVE-2015-0404 |
| oracle -- jdk |
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality and availability via unknown vectors related to Deployment. |
2015年01月21日 |
5.8 |
CVE-2015-0406 |
| oracle -- jdk |
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Swing. |
2015年01月21日 |
5.0 |
CVE-2015-0407 |
| oracle -- mysql |
Unspecified vulnerability in Oracle MySQL Server 5.6.21 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer. |
2015年01月21日 |
4.0 |
CVE-2015-0409 |
| oracle -- jdk |
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security. |
2015年01月21日 |
5.0 |
CVE-2015-0410 |
| oracle -- e-business_suite |
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Session Management. |
2015年01月21日 |
4.0 |
CVE-2015-0415 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Portal Framework, a different vulnerability than CVE-2015-0388. |
2015年01月21日 |
4.0 |
CVE-2015-0417 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Portal Framework. |
2015年01月21日 |
4.3 |
CVE-2015-0419 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle Forms component in Oracle Fusion Middleware 11.1.1.7 and 11.1.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Forms Services. |
2015年01月21日 |
4.3 |
CVE-2015-0420 |
| oracle -- jdk |
Unspecified vulnerability in Oracle Java SE 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the installation process. |
2015年01月21日 |
6.9 |
CVE-2015-0421 |
| oracle -- supply_chain_products_suite |
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, and 6.3.5 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Infrastructure. |
2015年01月21日 |
4.0 |
CVE-2015-0422 |
| oracle -- siebel_crm |
Unspecified vulnerability in the Oracle Enterprise Asset Management component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Siebel Core - Unix/Windows. |
2015年01月21日 |
4.3 |
CVE-2015-0425 |
| oracle -- enterprise_manager_grid_control |
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.3 and 12.1.0.4 allows remote attackers to affect confidentiality via unknown vectors related to UI Framework. |
2015年01月21日 |
5.0 |
CVE-2015-0426 |
| oracle -- supply_chain_products_suite |
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0 6.3.1, 6.3.2, 6.3.4, and 6.3.5 allows remote attackers to affect integrity via unknown vectors related to UI Infrastructure. |
2015年01月21日 |
4.3 |
CVE-2015-0431 |
| oracle -- mysql |
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key. |
2015年01月21日 |
4.0 |
CVE-2015-0432 |
| oracle -- fusion_middleware |
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to affect confidentiality via vectors related to Integration with OAM. |
2015年01月21日 |
4.3 |
CVE-2015-0434 |
| oracle -- supply_chain_products_suite |
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, and 6.3.5 allows remote authenticated users to affect confidentiality via unknown vectors related to Security. |
2015年01月21日 |
6.8 |
CVE-2015-0435 |
| oracle -- ilearning |
Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect confidentiality via unknown vectors related to Login. |
2015年01月21日 |
4.3 |
CVE-2015-0436 |
| pax_project -- pax |
Multiple directory traversal vulnerabilities in pax 1:20140703 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive. |
2015年01月21日 |
5.0 |
CVE-2015-1193 MISC MLIST |
| pax_project -- pax |
pax 1:20140703 allows remote attackers to write to arbitrary files via a symlink attack in an archive. |
2015年01月21日 |
4.3 |
CVE-2015-1194 MISC MLIST |
| pivotal_software -- rabbitmq |
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header. |
2015年01月20日 |
5.0 |
CVE-2014-9494 CONFIRM XF MLIST |
| privoxy -- privoxy |
Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy before 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests that are rejected because the socket limit is reached. |
2015年01月20日 |
5.0 |
CVE-2015-1030 MLIST SECUNIA |
| privoxy -- privoxy |
Privoxy before 3.0.22 allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |
2015年01月20日 |
5.0 |
CVE-2015-1201 SECUNIA |
| puppetlabs -- stdlib |
The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to gain privileges or obtain sensitive information by prepopulating the fact cache. |
2015年01月16日 |
6.5 |
CVE-2015-1029 SECUNIA |
| python -- pillow |
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed. |
2015年01月16日 |
5.0 |
CVE-2014-9601 CONFIRM CONFIRM |
| redhat -- cloudforms_3.1_management_engine |
SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to execute arbitrary SQL commands via a crafted REST API request to an SQL filter. |
2015年01月16日 |
6.5 |
CVE-2014-7814 SECUNIA |
| sap -- netweaver_abap |
XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATT_DISPLAY_XMLSTRING_REMOTE, aka SAP Note 2016638. |
2015年01月22日 |
5.0 |
CVE-2015-1309 SECUNIA MISC MISC |
| serve-static_project -- serve-static |
Open redirect vulnerability in the serve-static plugin before 1.7.2 for Node.js, when mounted at the root, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the PATH_INFO to the default URI. |
2015年01月21日 |
4.3 |
CVE-2015-1164 CONFIRM CONFIRM XF BID CONFIRM |
| siemens -- scalance_x-300_series_firmware |
The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authenticated users to cause a denial of service (reboot) via crafted FTP packets. |
2015年01月21日 |
6.8 |
CVE-2014-8479 |
| siemens -- simatic_s7_1200_cpu_firmware |
Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. |
2015年01月21日 |
4.3 |
CVE-2015-1048 |
| sun -- sunos |
Unspecified vulnerability in Oracle Solaris 10 and 11 allows remote attackers to affect confidentiality via vectors related to KSSL. |
2015年01月21日 |
4.3 |
CVE-2014-6481 |
| sun -- sunos |
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability via unknown vectors related to Kernel. |
2015年01月21日 |
4.9 |
CVE-2014-6509 |
| sun -- sunos |
Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and availability via vectors related to Unix File System (UFS). |
2015年01月21日 |
6.6 |
CVE-2014-6518 |
| sun -- sunos |
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to File System, a different vulnerability than CVE-2014-6600 and CVE-2015-0397. |
2015年01月21日 |
4.9 |
CVE-2014-6570 |
| sun -- sunos |
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via unknown vectors related to Network, a different vulnerability than CVE-2004-0230. |
2015年01月21日 |
5.0 |
CVE-2014-6575 |
| sun -- sunos |
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to File System, a different vulnerability than CVE-2014-6570 and CVE-2015-0397. |
2015年01月21日 |
4.9 |
CVE-2014-6600 |
| sun -- sunos |
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect confidentiality via unknown vectors related to Network. |
2015年01月21日 |
5.0 |
CVE-2015-0375 |
| sun -- sunos |
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Resource Control. |
2015年01月21日 |
4.9 |
CVE-2015-0428 |
| symantec -- critical_system_protection |
SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request. |
2015年01月21日 |
6.5 |
CVE-2014-7289 BID |
| symantec -- critical_system_protection |
The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server information via unspecified vectors. |
2015年01月21日 |
4.0 |
CVE-2014-9225 BID |
| sympa -- sympa |
The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors. |
2015年01月22日 |
5.0 |
CVE-2015-1306 MLIST DEBIAN SECUNIA SECUNIA |
| synck_graphica -- download_log_cgi |
Directory traversal vulnerability in SYNCK GRAPHICA Download Log CGI 3.0 and earlier allows remote attackers to read arbitrary files via a crafted filename. |
2015年01月21日 |
5.0 |
CVE-2015-0867 |
| videolan -- vlc_media_player |
The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP violation and application crash) via a crafted FLV file. |
2015年01月21日 |
6.8 |
CVE-2014-9597 MISC MISC MISC FULLDISC |
| videolan -- vlc_media_player |
The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access violation) via a crafted M2V file. |
2015年01月21日 |
6.8 |
CVE-2014-9598 MISC MISC MISC FULLDISC |
| websitebaker -- websitebaker |
Cross-site scripting (XSS) vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 SP3 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter. |
2015年01月21日 |
4.3 |
CVE-2015-0553 MISC BID MISC MISC FULLDISC MISC |
| zlib -- pigz |
Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive. |
2015年01月21日 |
5.0 |
CVE-2015-1191 CONFIRM CONFIRM MLIST |