Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2015-02-11 CVE-2015-0018 Resource Management Errors vulnerability in Microsoft Internet Explorer 11
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0037, CVE-2015-0040, and CVE-2015-0066.
network
microsoft CWE-399
critical
9.3
2015-02-11 CVE-2015-0017 Resource Management Errors vulnerability in Microsoft Internet Explorer
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0020, CVE-2015-0022, CVE-2015-0026, CVE-2015-0030, CVE-2015-0031, CVE-2015-0036, and CVE-2015-0041.
network
microsoft CWE-399
critical
9.3
2015-02-07 CVE-2015-0589 Improper Input Validation vulnerability in Cisco Webex Meetings Server 1.0/1.1/1.5
The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authenticated users to execute arbitrary OS commands with root privileges via unspecified fields, aka Bug ID CSCuj40460.
network
low complexity
cisco CWE-20
critical
9.0
2015-02-06 CVE-2014-9353 Permissions, Privileges, and Access Controls vulnerability in Netapp Oncommand Balance 4.2
NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vectors.
network
low complexity
netapp CWE-264
critical
10.0
2015-02-06 CVE-2014-0605 Path Traversal vulnerability in Attachmate Reflection FTP Client
Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the SaveSettings method.
network
low complexity
attachmate CWE-22
critical
10.0
2015-02-06 CVE-2014-0604 Path Traversal vulnerability in Attachmate Reflection FTP Client
Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the StartLog method.
network
low complexity
attachmate CWE-22
critical
10.0
2015-02-06 CVE-2014-0603 Code Injection vulnerability in Attachmate Reflection FTP Client
The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (memory corruption) and execute arbitrary code via vectors related to the (1) GetGlobalSettings or (2) GetSiteProperties3 methods, which triggers a dereference of an arbitrary memory address.
network
low complexity
attachmate CWE-94
critical
10.0
2015-02-06 CVE-2015-0330 Security vulnerability in Adobe Flash Player
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0318, CVE-2015-0321, and CVE-2015-0329.
network
low complexity
adobe apple microsoft linux
critical
10.0
2015-02-06 CVE-2015-0329 Security vulnerability in Adobe Flash Player
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0314, CVE-2015-0316, CVE-2015-0318, CVE-2015-0321, and CVE-2015-0330.
network
low complexity
adobe linux apple microsoft
critical
10.0
2015-02-06 CVE-2015-0328 Security vulnerability in Adobe Flash Player
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2015-0325 and CVE-2015-0326.
network
low complexity
adobe apple microsoft linux
critical
10.0