|
211921
|
5.5 |
MEDIUM
Local
|
stalin_project
|
stalin
|
stalin 0.11-5 allows local users to write to arbitrary files.
|
CWE-284
Improper Access Control
|
CVE-2015-8697
|
2024-11-21 11:38 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211922
|
6.5 |
MEDIUM
Network
|
libdwarf_project
|
libdwarf
|
dwarf_leb.c in libdwarf allows attackers to cause a denial of service (SIGSEGV).
|
CWE-20
Improper Input Validation
|
CVE-2015-8538
|
2024-11-21 11:38 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211923
|
7.5 |
HIGH
Network
|
call-cc
|
spiffy
|
Directory traversal vulnerability in Spiffy before 5.4.
|
CWE-22
Path Traversal
|
CVE-2015-8235
|
2024-11-21 11:38 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211924
|
5.5 |
MEDIUM
Local
|
iptables-parse_project
|
iptables-parse_module
|
The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.
|
CWE-59
Link Following
|
CVE-2015-8326
|
2024-11-21 11:38 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211925
|
6.1 |
MEDIUM
Network
|
redmine
|
redmine
|
Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving flash message rendering.
|
CWE-79
Cross-site Scripting
|
CVE-2015-8477
|
2024-11-21 11:38 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211926
|
7.8 |
HIGH
Local
|
huawei
|
p7-l09_firmware p7-l05_firmware p7-l00_firmware
|
The GPU driver in Huawei P7 phones with software P7-L00 before P7-L00C17B851, P7-L05 before P7-L05C00B851, and P7-L09 before P7-L09C92B851 allows local users to read or write to arbitrary kernel memo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8089
|
2024-11-21 11:38 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211927
|
8.8 |
HIGH
Network
|
axis
|
network_camera_firmware
|
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_…
|
CWE-77
Command Injection
|
CVE-2015-8257
|
2024-11-21 11:38 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211928
|
7.8 |
HIGH
Local
|
lenovo
|
lenovo_system_update
|
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8110
|
2024-11-21 11:38 |
2017-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211929
|
7.0 |
HIGH
Local
|
lenovo
|
lenovo_system_update
|
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowl…
|
CWE-255
Credentials Management
|
CVE-2015-8109
|
2024-11-21 11:38 |
2017-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211930
|
7.5 |
HIGH
Network
|
quickheal
|
total_security
|
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8285
|
2024-11-21 11:38 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|