|
212551
|
- |
|
newphoria_corporation
|
applican
|
Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7771
|
2024-11-21 11:37 |
2015-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212552
|
- |
|
huawei
|
ne_router_software
|
Huawei NE20E-S, NE40E-M, and NE40E-M2 routers with software before V800R007C10SPC100 and NE40E and NE80E routers with software before V800R007C00SPC100 allows remote attackers to send packets to othe…
|
CWE-399
Resource Management Errors
|
CVE-2015-8087
|
2024-11-21 11:37 |
2015-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212553
|
- |
|
huawei
|
espace_firmware
|
An unspecified module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways with software before V200R003C00SPC300 does not properly initialize memory when processing timeout…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8083
|
2024-11-21 11:37 |
2015-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212554
|
- |
|
horde debian
|
horde_application_framework groupware debian_linux
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the…
|
CWE-352
Origin Validation Error
|
CVE-2015-7984
|
2024-11-21 11:37 |
2015-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212555
|
- |
|
huawei
|
espace_firmware
|
The exception handling mechanism in the CLI Module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways with software before V100R001C20SPH605 allows remote attackers to cau…
|
CWE-20
Improper Input Validation
|
CVE-2015-7845
|
2024-11-21 11:37 |
2015-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212556
|
- |
|
exemys
|
telemetry_web_server
|
Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass intended access restrictions by disregarding this head…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2015-7910
|
2024-11-21 11:37 |
2015-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212557
|
- |
|
adobe
|
coldfusion
|
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a diffe…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8053
|
2024-11-21 11:37 |
2015-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212558
|
- |
|
adobe
|
coldfusion
|
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a diffe…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8052
|
2024-11-21 11:37 |
2015-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212559
|
- |
|
adobe
|
premiere_clip
|
The Adobe Premiere Clip app before 1.2.1 for iOS mishandles unspecified input, which has unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2015-8051
|
2024-11-21 11:37 |
2015-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212560
|
- |
|
debian xmlsoft apple canonical
|
debian_linux libxml2 watchos iphone_os mac_os_x tvos ubuntu_linux
|
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML da…
|
CWE-399
Resource Management Errors
|
CVE-2015-8035
|
2024-11-21 11:37 |
2015-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|