LiveActive security incident?Get immediate response
CVE archive

May 2015

Browse CVE records published in May 2015, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 507 matching CVEs · Page 7 of 11.

Unknown · CVSS Not scored

CVE-2015-2712: The asm.js implementation in Mozilla Firefox before 38.0 does not properly determine heap lengths during id...

The asm.js implementation in Mozilla Firefox before 38.0 does not properly determine heap lengths during identification of cases in which bounds checking may be safely skipped, which allows remote attackers to trigger out-of-bounds write operations and possibly execute arbitrary code, or trigger out-of-bounds read operations and possibly obtain sensitive information from process memory, via crafted JavaScript.

Published May 14, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-2672: The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates c...

The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altinstr_replacement pointers and consequently does not provide any protection against instruction faulting, which allows local users to cause a denial of service (panic) by triggering a fault, as demonstrated by an unaligned memory operand or a non-canonical address memory operand.

Published May 2, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-2666: Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/i...

Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing a crafted microcode header and leveraging root privileges for write access to the initrd.

Published May 27, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-2347: Cross-site scripting (XSS) vulnerability in Huawei SEQ Analyst before V200R002C03LG0001CP0022 allows remote...

Cross-site scripting (XSS) vulnerability in Huawei SEQ Analyst before V200R002C03LG0001CP0022 allows remote attackers to inject arbitrary web script or HTML via the command XML element in the req parameter to flexdata.action in (1) common/, (2) monitor/, or (3) psnpm/ or the (4) module XML element in the req parameter to flexdata.action in monitor/.

Published May 8, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-2248: Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (...

Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0-38sv and 8.x before 8.0.0.1-16sv allows remote attackers to hijack the authentication of users for requests that create bookmarks via a crafted request to cgi-bin/editBookmark.

Published May 1, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-2250: Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inj...

Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) banned_word[] parameter to index.php/dashboard/system/conversations/bannedwords/success, (2) channel parameter to index.php/dashboard/reports/logs/view, (3) accessType parameter to index.php/tools/required/permissions/access_entity, (4) msCountry parameter to index.php/dashboard/system/multilingual/setup/load_icon, arHandle parameter to (5) design/submit or (6) design in index.php/ccm/system/dialogs/area/design/submit, (7) pageURL to index.php/dashboard/pages/single, (8) SEARCH_INDEX_AREA_METHOD parameter to index.php/dashboard/system/seo/searchindex/updated, (9) unit parameter to index.php/dashboard/system/optimization/jobs/job_scheduled, (10) register_notification_email parameter to index.php/dashboard/system/registration/open/1, or (11) PATH_INFO to index.php/dashboard/extend/connect/.

Published May 15, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1937: IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require...

IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote attackers to read or write to arbitrary database records, and consequently obtain administrator privileges, via a session on port 27017.

Published May 30, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1915: The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9...

The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

Published May 25, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1909: The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Manag...

The XML parser in the Reference Data Management component in the server in IBM InfoSphere Master Data Management (MDM) 10.1 before IF1, 11.0 before FP3, 11.3, and 11.4 before FP2 allows remote attackers to read arbitrary files, and consequently obtain administrative access, via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Published May 25, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1911: Cross-site scripting (XSS) vulnerability in Sterling Order Management 8.5 before HF113, Sterling Selling an...

Cross-site scripting (XSS) vulnerability in Sterling Order Management 8.5 before HF113, Sterling Selling and Fulfillment Foundation 9.0.0 before FP92, and Sterling Field Sales (SFS) 9.0 before HF7 in IBM Sterling Selling and Fulfillment Suite allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Published May 25, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1868: The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7....

The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.

Published May 18, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1848: The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https sess...

The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.

Published May 14, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1834: A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects...

A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects cf-release versions prior to v208 and Pivotal Cloud Foundry Elastic Runtime versions prior to 1.4.2. Path traversal is the 'outbreak' of a given directory structure through relative file paths in the user input. It aims at accessing files and directories that are stored outside the web root folder, for disallowed reading or even executing arbitrary system commands. An attacker could use a certain parameter of the file path for instance to inject '../' sequences in order to navigate through the file system. In this particular case a remote authenticated attacker can exploit the identified vulnerability in order to upload arbitrary files to the server running a Cloud Controller instance - outside the isolated application container.

Published May 25, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-1706: Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of servi...

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1658, CVE-2015-1711, CVE-2015-1717, and CVE-2015-1718.

Published May 13, 2015 · Updated Aug 6, 2024