LiveActive security incident?Get immediate response
CVE archive

August 2015

Browse CVE records published in August 2015, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 876 matching CVEs · Page 5 of 18.

Unknown · CVSS Not scored

CVE-2015-7255: ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X....

ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device.

Published Aug 29, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-6747: Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows re...

Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows remote attackers to spoof communications with banks via unspecified vectors. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 due to different vulnerability types. NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-6746.

Published Aug 31, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-6742: Basware Banking (Maksuliikenne) before 8.90.07.X uses a hardcoded password for the ANCO account, which allo...

Basware Banking (Maksuliikenne) before 8.90.07.X uses a hardcoded password for the ANCO account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability types and different affected versions.

Published Aug 31, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-6744: Basware Banking (Maksuliikenne) before 8.90.07.X relies on the client to enforce (1) login verification, (2...

Basware Banking (Maksuliikenne) before 8.90.07.X relies on the client to enforce (1) login verification, (2) audit trail creation, and (3) account locking, which allows remote attackers to "disrupt security-critical functions" by "dropping network traffic." NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability type and different affected versions.

Published Aug 31, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-6743: Basware Banking (Maksuliikenne) 8.90.07.X uses a hardcoded password for an unspecified account, which allow...

Basware Banking (Maksuliikenne) 8.90.07.X uses a hardcoded password for an unspecified account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability types and different affected versions.

Published Aug 31, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-6745: Basware Banking (Maksuliikenne) 8.90.07.X relies on the client to enforce account locking, which allows loc...

Basware Banking (Maksuliikenne) 8.90.07.X relies on the client to enforce account locking, which allows local users to bypass that security mechanism by deleting the entry from the locking table. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability type and different affected versions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-6744.

Published Aug 31, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-6751: Multiple cross-site scripting (XSS) vulnerabilities in the Time Tracker module 7.x-1.x before 7.x-1.4 for D...

Multiple cross-site scripting (XSS) vulnerabilities in the Time Tracker module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) note added to a time entry or an (2) activity used to categorize time tracker entries.

Published Aug 31, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-6557: IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3...

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; and Tivoli Storage FlashCopy Manager 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.2, when application tracing is used, place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading trace output, a different vulnerability than CVE-2015-4949.

Published Aug 23, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-6524: The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache Ac...

The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.

Published Aug 24, 2015 · Updated Aug 6, 2024