LiveActive security incident?Get immediate response
CVE archive

January 2015

Browse CVE records published in January 2015, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 701 matching CVEs · Page 3 of 15.

Medium · CVSS 5.5

CVE-2015-10022: IISH nlgis2 custom_import.pl sql injection

A vulnerability was found in IISH nlgis2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file scripts/etl/custom_import.pl. The manipulation leads to sql injection. The identifier of the patch is 8bdb6fcf7209584eaf1232437f0f53e735b2b34c. It is recommended to apply a patch to fix this issue. The identifier VDB-217609 was assigned to this vulnerability.

Published Jan 7, 2023 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-9276: SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms.

SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms. It was possible to run JavaScript code when a victim user opens or replies to the attacker's email, which contained a malicious payload. Therefore, users' passwords could be reset by using an XSS attack, as the password reset page did not need the current password.

Published Jan 16, 2019 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-9246: An issue was discovered in Skybox Platform before 7.5.201.

An issue was discovered in Skybox Platform before 7.5.201. Remote Unauthenticated Code Execution exists via a WAR archive containing a JSP file. The WAR file is sent to /skyboxview-softwareupdate/services/CollectorSoftwareUpdate and the JSP file is reached at /opt/skyboxview/thirdparty/jboss/server/web/work/jboss.web/localhost.

Published Jan 12, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-9247: An issue was discovered in Skybox Platform before 7.5.401.

An issue was discovered in Skybox Platform before 7.5.401. Reflected cross-site scripting vulnerabilities exist in /skyboxview/webservice/services/VersionRepositoryWebService via a soapenv:Body element, or in the status parameter to login.html.

Published Jan 12, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-8766: Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CM...

Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) email_sendmail[from_name], (2) email_sendmail[from_address], (3) email_smtp[from_name], (4) email_smtp[from_address], (5) email_smtp[host], (6) email_smtp[port], (7) jit_image_manipulation[trusted_external_sites], or (8) maintenance_mode[ip_whitelist] parameters to system/preferences.

Published Jan 8, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-8770: Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Rou...

Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.

Published Jan 29, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-8729: The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12....

The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not ensure the presence of a '\0' character at the end of a date string, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.

Published Jan 4, 2016 · Updated Aug 6, 2024