LiveActive security incident?Get immediate response
CVE archive

October 2015

Browse CVE records published in October 2015, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 929 matching CVEs · Page 3 of 19.

Unknown · CVSS Not scored

CVE-2015-9271: The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attack...

The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code, a different vulnerability than CVE-2014-1905.

Published Oct 4, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-8951: Multiple use-after-free vulnerabilities in sound/soc/msm/qdsp6v2/msm-lsm-client.c in the Qualcomm sound dri...

Multiple use-after-free vulnerabilities in sound/soc/msm/qdsp6v2/msm-lsm-client.c in the Qualcomm sound driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 30142668 and Qualcomm internal bug CR 948902.

Published Oct 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-8086: Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R0...

Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 makes it easier for remote authenticated administrators to obtain encryption keys and ciphertext passwords via vectors related to key storage.

Published Oct 3, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-8085: Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R0...

Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 make it easier for remote authenticated administrators to obtain and decrypt passwords by leveraging selection of a reversible encryption algorithm.

Published Oct 3, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-7971: Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and p...

Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and profiling hypercalls, which allows local guests to cause a denial of service via a sequence of crafted (1) HYPERCALL_xenoprof_op hypercalls, which are not properly handled in the do_xenoprof_op function in common/xenoprof.c, or (2) HYPERVISOR_xenpmu_op hypercalls, which are not properly handled in the do_xenpmu_op function in arch/x86/cpu/vpmu.c.

Published Oct 30, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-7970: The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preempt...

The p2m_pod_emergency_sweep function in arch/x86/mm/p2m-pod.c in Xen 3.4.x, 3.5.x, and 3.6.x is not preemptible, which allows local x86 HVM guest administrators to cause a denial of service (CPU consumption and possibly reboot) via crafted memory contents that triggers a "time-consuming linear scan," related to Populate-on-Demand.

Published Oct 30, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-7969: Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain per...

Multiple memory leaks in Xen 4.0 through 4.6.x allow local guest administrators or domains with certain permission to cause a denial of service (memory consumption) via a large number of "teardowns" of domains with the vcpu pointer array allocated using the (1) XEN_DOMCTL_max_vcpus hypercall or the xenoprofile state vcpu pointer array allocated using the (2) XENOPROF_get_buffer or (3) XENOPROF_set_passive hypercall.

Published Oct 30, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2015-7972: The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools...

The (1) libxl_set_memory_target function in tools/libxl/libxl.c and (2) libxl__build_post function in tools/libxl/libxl_dom.c in Xen 3.4.x through 4.6.x do not properly calculate the balloon size when using the populate-on-demand (PoD) system, which allows local HVM guest users to cause a denial of service (guest crash) via unspecified vectors related to "heavy memory pressure."

Published Oct 30, 2015 · Updated Aug 6, 2024