CVE-2015-0884
Last modified
CVE-2015-0884 is a vulnerability of currently unknown severity. Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Toshiba | Bluetooth Stack | 9.10.27\(t\) |
| Toshiba | Service Station | <= 2.2.13 |
References
- http://www.kb.cert.org/vuls/id/632140Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/632140Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0884?
How severe is CVE-2015-0884?
How do I fix CVE-2015-0884?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-0878Directory traversal vulnerability in CREAR AL-Mail32 before …
- CVE-2015-0879CREAR AL-Mail32 before 1.13d allows remote attackers to caus…
- CVE-2015-0880Buffer overflow in CREAR AL-Mail32 before 1.13d allows remot…
- CVE-2015-0881CRLF injection vulnerability in Squid before 3.1.1 allows re…
- CVE-2015-0882Multiple cross-site scripting (XSS) vulnerabilities in zenca…
- CVE-2015-0883SYNCK GRAPHICA Mailform Pro CGI 4.1.4 and 4.1.5, when the ma…
- CVE-2015-0885checkpw 1.02 and earlier allows remote attackers to cause a …
- CVE-2015-0886Integer overflow in the crypt_raw method in the key-stretchi…
- CVE-2015-0887npppd in the PPP Access Concentrator (PPPAC) on SEIL SEIL/x8…
- CVE-2015-0888KENT-WEB Clip Board before 4.1 allows remote attackers to de…
- CVE-2015-0889KENT-WEB Joyful Note before 5.3 allows remote attackers to d…
- CVE-2015-0890The BestWebSoft Google Captcha (aka reCAPTCHA) plugin before…
Are you affected by CVE-2015-0884?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
