Skip to main content

Year archive

CVEs published in 2015

Archive summary

6,494 CVEs published in 2015 — 1,148 Critical, 1,254 High, 3,504 Medium, 588 Low, 0 Unrated.

CVE-2014-8914

Published Jan 21, 2015

Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated us…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-8913

Published Jan 21, 2015

Cross-site scripting (XSS) vulnerability in the Process Portal in IBM Business Process Manager 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 allows remote authenticated us…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-6172

Published Jan 21, 2015

IBM API Management 3.0 before 3.0.4.0 IF1 allows remote attackers to obtain sensitive analytics information in an encrypted form via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6528

Published Jan 21, 2015

Unspecified vulnerability in the Siebel Core - System Management component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unk…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6526

Published Jan 21, 2015

Unspecified vulnerability in the Oracle Directory Server Enterprise Edition component in Oracle Fusion Middleware 7.0 allows remote attackers to affect integrity via unknown vecto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6525

Published Jan 21, 2015

Unspecified vulnerability in the Oracle Web Applications Desktop Integrator component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remot…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-6524

Published Jan 21, 2015

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6521

Published Jan 21, 2015

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via vectors related to CDE - Power Management Utility.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6518

Published Jan 21, 2015

Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and availability via vectors related to Unix File System (UFS).

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6514

Published Jan 21, 2015

Unspecified vulnerability in the PL/SQL component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6510

Published Jan 21, 2015

Unspecified vulnerability in Oracle Solaris 11 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Power Management Utility.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6509

Published Jan 21, 2015

Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability via unknown vectors related to Kernel.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6481

Published Jan 21, 2015

Unspecified vulnerability in Oracle Solaris 10 and 11 allows remote attackers to affect confidentiality via vectors related to KSSL.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6480

Published Jan 21, 2015

Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.1 allows local users to affect confidentiality, integrity, and availabili…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4279

Published Jan 21, 2015

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 allows remote authenticated users to affect integrity via vectors r…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-4259

Published Jan 21, 2015

Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.1 allows remote authenticated users to affect confidentiality, integrity,…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0191

Published Jan 21, 2015

The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-1201

Published Jan 20, 2015

Privoxy before 3.0.22 allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors. NOTE: the provenance of this information is unkn…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1030

Published Jan 20, 2015

Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy before 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9494

Published Jan 20, 2015

RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9491

Published Jan 20, 2015

The devzvol_readdir function in illumos does not check the return value of a strchr call, which allows remote attackers to cause a denial of service (NULL pointer dereference and…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 6,076-6,100 of 6,494 CVEsPage 244 of 260