Skip to main content

Year archive

CVEs published in 2015

Archive summary

6,494 CVEs published in 2015 — 1,148 Critical, 1,254 High, 3,504 Medium, 588 Low, 0 Unrated.

CVE-2014-9490

Published Jan 20, 2015

The numtok function in lib/raven/okjson.rb in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a large exponent value in a scient…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9330

Published Jan 20, 2015

Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which tri…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8625

Published Jan 20, 2015

Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possib…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8386

Published Jan 20, 2015

Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditiona…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0862

Published Jan 18, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary we…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-7252

Published Jan 18, 2015

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to gues…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0590

Published Jan 17, 2015

Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providing crafted parameters during a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3032

Published Jan 17, 2015

Cross-site scripting (XSS) vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus 7.3.0 before 7.3.0.6, 7.3.1 before 7.3.1.7, and 7.4.0 before 7.4.0.3 allows remote authentica…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-9194

Published Jan 17, 2015

Arbiter 1094B GPS Substation Clock allows remote attackers to cause a denial of service (disruption) via crafted radio transmissions that spoof GPS satellite broadcasts.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-8143

Published Jan 17, 2015

Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-5419

Published Jan 17, 2015

GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the sa…

CVSS 10.0 · Critical

CVE-2014-5418

Published Jan 17, 2015

GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remo…

CVSS 5.0 · Medium

CVE-2014-9604

Published Jan 16, 2015

libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of service (out-of-bounds array a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9603

Published Jan 16, 2015

The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the frame width, which allows remote…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9602

Published Jan 16, 2015

libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words array dimensions that do not satisfy a required mathematical relationship, which allows remote attac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 6,101-6,125 of 6,494 CVEsPage 245 of 260