Skip to main content

Year archive

CVEs published in 2015

Archive summary

6,494 CVEs published in 2015 — 1,148 Critical, 1,254 High, 3,504 Medium, 588 Low, 0 Unrated.

CVE-2015-1029

Published Jan 16, 2015

The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to gain privileges or obtain sensi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0222

Published Jan 16, 2015

ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by sub…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0220

Published Jan 16, 2015

The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote at…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0219

Published Jan 16, 2015

Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 allows remote attackers to spoof WSGI headers by using an _ (underscore) character instead of a - (dash) characte…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9480

Published Jan 16, 2015

Cross-site scripting (XSS) vulnerability in the Hovercards extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors related to text extra…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9479

Published Jan 16, 2015

Cross-site scripting (XSS) vulnerability in the preview in the TemplateSandbox extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via the text…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9478

Published Jan 16, 2015

Cross-site scripting (XSS) vulnerability in the preview in the ExpandTemplates extension for MediaWiki, when $wgRawHTML is set to true, allows remote attackers to inject arbitrary…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-9477

Published Jan 16, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the Listings extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9476

Published Jan 16, 2015

MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAXdomains via a domain that has…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9475

Published Jan 16, 2015

Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.19.23, 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote authenticated…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-9471

Published Jan 16, 2015

The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-7814

Published Jan 16, 2015

SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to execute arbitrary SQL commands via a crafted REST API reque…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6386

Published Jan 16, 2015

Juniper Junos 11.4 before 11.4R8, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R9, 12.3R2 before…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6385

Published Jan 16, 2015

Juniper Junos 11.4 before 11.4R13, 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, 12.2 before 12.2R9, 12.3R7 before 12.3R7-S1, 12.3 before 12.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6384

Published Jan 16, 2015

Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D15, 12.3 before 12.3R9, 13.1 before 13.1R4-S3, 13.2 before 13.2R6, 13.3 before 13.3R5…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6383

Published Jan 16, 2015

The stateless firewall in Juniper Junos 13.3R3, 14.1R1, and 14.1R2, when using Trio-based PFE modules, does not properly match ports, which might allow remote attackers to bypass…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3692

Published Jan 16, 2015

The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not specified for a new image, wh…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1060

Published Jan 16, 2015

Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks v…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1059

Published Jan 16, 2015

Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extensio…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1058

Published Jan 16, 2015

Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Category][title] parameter to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 6,126-6,150 of 6,494 CVEsPage 246 of 260