|
212101
|
7.5 |
HIGH
Network
|
huawei
|
espace_7950 espace_7910
|
Huawei eSpace 7910 and 7950 IP phones with software before V200R002C00SPC800 allow remote attackers with established sessions to cause a denial of service (device restart) via unspecified packets.
|
CWE-399
Resource Management Errors
|
CVE-2015-8231
|
2024-11-21 11:38 |
2016-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212102
|
7.5 |
HIGH
Network
|
huawei
|
espace_8950
|
Memory leak in Huawei eSpace 8950 IP phones with software before V200R003C00SPC300 allows remote attackers to cause a denial of service (memory consumption and restart) via a large number of crafted …
|
CWE-399
Resource Management Errors
|
CVE-2015-8230
|
2024-11-21 11:38 |
2016-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212103
|
4.6 |
MEDIUM
Physics
|
mozilla
|
firefox_os
|
The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by enterin…
|
CWE-284
Improper Access Control
|
CVE-2015-8512
|
2024-11-21 11:38 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212104
|
6.4 |
MEDIUM
Physics
|
mozilla
|
firefox_os
|
Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.
|
CWE-362
Race Condition
|
CVE-2015-8511
|
2024-11-21 11:38 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212105
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox_os
|
Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescreen app in Mozilla Firefox OS before 2.5 allows user-assisted remote attackers to inject arbitrary w…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8510
|
2024-11-21 11:38 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212106
|
6.1 |
MEDIUM
Network
|
getsymphony
|
symphony
|
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Navigation Group, or (3) Label parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2015-8376
|
2024-11-21 11:38 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212107
|
9.0 |
CRITICAL
Network
|
canonical pygments
|
ubuntu_linux pygments
|
The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
|
CWE-78
OS Command
|
CVE-2015-8557
|
2024-11-21 11:38 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212108
|
9.8 |
CRITICAL
Network
|
libtiff oracle redhat
|
libtiff vm_server linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux
|
Heap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attackers to execute arbitrary code or cause a denial of service …
|
CWE-787
Out-of-bounds Write
|
CVE-2015-8668
|
2024-11-21 11:38 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212109
|
5.0 |
MEDIUM
Network
|
xen
|
xen
|
The hvm_set_callback_via function in arch/x86/hvm/irq.c in Xen 4.6 does not limit the number of printk console messages when logging the new callback method, which allows local HVM guest OS users to …
|
CWE-254
7PK - Security Features
|
CVE-2015-8615
|
2024-11-21 11:38 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212110
|
8.4 |
HIGH
Local
|
blueman_project
|
blueman
|
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users to gain privileges via the dhcp_handler argument.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8612
|
2024-11-21 11:38 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|