CVE-2015-6946
Last modified
CVE-2015-6946 is a vulnerability of currently unknown severity. Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary code via the (1) akey or (2) actserver parameter to the activate_doit function or (3) licfile parameter to the service_startup_doit functionality.. EPSS estimates a 19.98% chance of exploitation in the next 30 days.
Description
Multiple stack-based buffer overflows in the Reprise License Manager service in Borland AccuRev allow remote attackers to execute arbitrary code via the (1) akey or (2) actserver parameter to the activate_doit function or (3) licfile parameter to the service_startup_doit functionality.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Accurev | All versions |
References
- http://www.zerodayinitiative.com/advisories/ZDI-15-412Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-15-414/Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-15-416Third Party Advisory, VDB Entry
- https://redr2e.com/cve-to-poc-cve-2015-6946/Exploit, Third Party Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-15-412Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-15-414/Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-15-416Third Party Advisory, VDB Entry
- https://redr2e.com/cve-to-poc-cve-2015-6946/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-6946?
How severe is CVE-2015-6946?
How do I fix CVE-2015-6946?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-6940The GetResource servlet in Pentaho Business Analytics (BA) S…
- CVE-2015-6941win_useradd, salt-cloud and the Linode driver in salt 2015.5…
- CVE-2015-6942Cross-site scripting (XSS) vulnerability in Coremail XT3.0 a…
- CVE-2015-6943SQL injection vulnerability in the serendipity_checkCommentT…
- CVE-2015-6944Cross-site request forgery (CSRF) vulnerability in JSP/MySQL…
- CVE-2015-6945Cross-site scripting (XSS) vulnerability in JSP/MySQL Admini…
- CVE-2015-6947Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-6948Heap-based buffer overflow in the Microsoft Word document co…
- CVE-2015-6949Stack-based buffer overflow in the ASUS TM-AC1900 router all…
- CVE-2015-6959Cross-site scripting (XSS) vulnerability in Vindula 1.9.
- CVE-2015-6960edx-platform before 2015-09-17 allows XSS via a team name.6.1
- CVE-2015-6961Open redirect vulnerability in gluon/tools.py in Web2py 2.9.…
Are you affected by CVE-2015-6946?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
