Skip to main content

Year archive

CVEs published in 2015

Archive summary

6,494 CVEs published in 2015 — 1,148 Critical, 1,254 High, 3,504 Medium, 588 Low, 0 Unrated.

CVE-2015-0004

Published Jan 13, 2015

The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows…

CVSS 7.2 · High

CVE-2014-10038

Published Jan 13, 2015

SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitrary SQL commands via the ids parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10037

Published Jan 13, 2015

Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a .. (dot dot) in the url parameter to photoalbum/index.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-10036

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in JetBrains TeamCity before 8.1 allows remote attackers to inject arbitrary web script or HTML via the cameFromUrl parameter to feed/gene…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10035

Published Jan 13, 2015

Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to inject arbitrary web script or HTML via the (1) sEch…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10034

Published Jan 13, 2015

Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execute arbitrary SQL commands via the (1) iDisplayLength or (2)…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10033

Published Jan 13, 2015

SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier allows remote administrators to execute ar…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10032

Published Jan 13, 2015

SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10031

Published Jan 13, 2015

Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary code via a long string in a UID command.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100039

Published Jan 13, 2015

mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a crafted size in an unspecified IOCTL call, which triggers an…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-100038

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in Storytlr 1.3.dev and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter to search/.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100037

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in Storytlr 1.3.dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to archives/.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100036

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in FlatPress 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the content parameter to the default URI.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100035

Published Jan 13, 2015

SQL injection vulnerability in the ticket grid in the admin interface in LicensePal ArcticDesk before 1.2.5 allows remote attackers to execute arbitrary SQL commands via unspecifi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100034

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in the frontend interface in LicensePal ArcticDesk before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via unspeci…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100033

Published Jan 13, 2015

Directory traversal vulnerability in LicensePal ArcticDesk before 1.2.5 allows remote attackers to read arbitrary files via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100032

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in top.html in the Airties Air 6372 modem allows remote attackers to inject arbitrary web script or HTML via the productboardtype paramete…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-100031

Published Jan 13, 2015

Multiple SQL injection vulnerabilities in Ganesha Digital Library (GDL) 4.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) download.php or (2…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-100028

Published Jan 13, 2015

Cross-site scripting (XSS) vulnerability in /signup in WEBCrafted allows remote attackers to inject arbitrary web script or HTML via the username.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 6,226-6,250 of 6,494 CVEsPage 250 of 260