|
212141
|
6.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and m…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8660
|
2024-11-21 11:38 |
2015-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212142
|
2.3 |
LOW
Local
|
linux
|
linux_kernel
|
The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel through 4.3.3 do not verify an address length, which allows local users to obtain sensitive information …
|
CWE-200
Information Exposure
|
CVE-2015-8569
|
2024-11-21 11:38 |
2015-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212143
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
The networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol identifiers for certain protocol families, which allows local users …
|
NVD-CWE-Other
|
CVE-2015-8543
|
2024-11-21 11:38 |
2015-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212144
|
4.0 |
MEDIUM
Local
|
linux
|
linux_kernel
|
fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.
|
CWE-200
Information Exposure
|
CVE-2015-8374
|
2024-11-21 11:38 |
2015-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212145
|
8.6 |
HIGH
Network
|
netgear
|
wnr1000v3_firmware wnr1000v3
|
NETGEAR WNR1000v3 devices with firmware 1.0.2.68 use the same source port number for every DNS query, which makes it easier for remote attackers to spoof responses by selecting that number for the de…
|
NVD-CWE-Other
|
CVE-2015-8263
|
2024-11-21 11:38 |
2015-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212146
|
6.8 |
MEDIUM
Network
|
buffalotech
|
airstation_extreme_n600_firmware airstation_extreme_n600
|
Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof r…
|
NVD-CWE-Other
|
CVE-2015-8262
|
2024-11-21 11:38 |
2015-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212147
|
5.9 |
MEDIUM
Network
|
rsi_video_technologies
|
frontel_protocol
|
The Frontel protocol before 3 on RSI Video Technologies Videofied devices does not use integrity protection, which makes it easier for man-in-the-middle attackers to (1) initiate a false alarm or (2)…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2015-8254
|
2024-11-21 11:38 |
2015-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212148
|
3.7 |
LOW
Network
|
rsi_video_technologies
|
frontel_protocol
|
The Frontel protocol before 3 on RSI Video Technologies Videofied devices sets up AES encryption but sends all traffic in cleartext, which allows remote attackers to obtain sensitive (1) message or (…
|
CWE-200
Information Exposure
|
CVE-2015-8253
|
2024-11-21 11:38 |
2015-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212149
|
5.9 |
MEDIUM
Network
|
rsi_video_technologies
|
frontel_protocol
|
The Frontel protocol before 3 on RSI Video Technologies Videofied devices sends a cleartext serial number, which allows remote attackers to determine a hardcoded key by sniffing the network and perfo…
|
CWE-200
Information Exposure
|
CVE-2015-8252
|
2024-11-21 11:38 |
2015-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212150
|
5.3 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to obtain sensitive information via a crafted request, …
|
CWE-200
Information Exposure
|
CVE-2015-8669
|
2024-11-21 11:38 |
2015-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|