Skip to main content

Year archive

CVEs published in 2015

Archive summary

6,494 CVEs published in 2015 — 1,148 Critical, 1,254 High, 3,504 Medium, 588 Low, 0 Unrated.

CVE-2014-6577

Published Jan 21, 2015

Unspecified vulnerability in the XML Developer's Kit for C component in Oracle Database Server 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affe…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6576

Published Jan 21, 2015

Unspecified vulnerability in the Oracle Adaptive Access Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote authenticated users…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6575

Published Jan 21, 2015

Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via unknown vectors related to Network, a different vulnerability than CVE…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6574

Published Jan 21, 2015

Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 6.1.0.3 allows remote attackers to affect integrity via unknown vecto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6573

Published Jan 21, 2015

Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 11.1.3 and 12.1.4 allows remote attackers to affect integrity vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6572

Published Jan 21, 2015

Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6571

Published Jan 21, 2015

Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect confidentiality, int…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6570

Published Jan 21, 2015

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to File System, a different vulnerability than CVE-2014-66…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6569

Published Jan 21, 2015

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confiden…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6567

Published Jan 21, 2015

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect co…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-6566

Published Jan 21, 2015

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 allows remote authenticated users to affect integrity via unknown v…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6565

Published Jan 21, 2015

Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1.5 allows remote attackers to affect confidentiality, integrity, and ava…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6556

Published Jan 21, 2015

Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated use…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6549

Published Jan 21, 2015

Unspecified vulnerability in Oracle Java SE 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-6548

Published Jan 21, 2015

Unspecified vulnerability in the Oracle SOA Suite component in Oracle Fusion Middleware 11.1.1.7 allows local users to affect confidentiality, integrity, and availability via vect…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6541

Published Jan 21, 2015

Unspecified vulnerability in the Recovery component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenti…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0867

Published Jan 21, 2015

Directory traversal vulnerability in SYNCK GRAPHICA Download Log CGI 3.0 and earlier allows remote attackers to read arbitrary files via a crafted filename.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0516

Published Jan 21, 2015

Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL.

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0515

Published Jan 21, 2015

Unrestricted file upload vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to execute arbitrary code by uploading a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0514

Published Jan 21, 2015

EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by leveraging certain SRM access…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0513

Published Jan 21, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allow remote authenticat…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-9598

Published Jan 21, 2015

The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (write access viol…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-9597

Published Jan 21, 2015

The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service (DEP viol…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 6,051-6,075 of 6,494 CVEsPage 243 of 260