|
211971
|
- |
|
apple
|
iwork pages
|
The Apple iWork application before 2.6 for iOS and Apple Pages before 5.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7034
|
2024-11-21 11:36 |
2015-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211972
|
- |
|
apple
|
numbers pages keynote iwork
|
The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of se…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7033
|
2024-11-21 11:36 |
2015-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211973
|
- |
|
apple
|
numbers iwork pages keynote
|
The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted doc…
|
CWE-200
Information Exposure
|
CVE-2015-7032
|
2024-11-21 11:36 |
2015-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211974
|
- |
|
mozilla
|
firefox
|
The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin re…
|
CWE-284
Improper Access Control
|
CVE-2015-7184
|
2024-11-21 11:36 |
2015-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211975
|
- |
|
genetechsolutions
|
pie_register
|
Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7377
|
2024-11-21 11:36 |
2015-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211976
|
- |
|
fortinet
|
fortios
|
FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the HA dedicated manag…
|
CWE-287
Improper Authentication
|
CVE-2015-7361
|
2024-11-21 11:36 |
2015-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211977
|
- |
|
revive-adserver
|
revive_adserver
|
Cross-site scripting (XSS) vulnerability in the "magic-macros" feature in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via a GET parameter, which is not…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7373
|
2024-11-21 11:36 |
2015-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211978
|
- |
|
revive-adserver
|
revive_adserver
|
Directory traversal vulnerability in delivery-dev/al.php in Revive Adserver before 3.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the layerstyle para…
|
CWE-22
Path Traversal
|
CVE-2015-7372
|
2024-11-21 11:36 |
2015-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211979
|
- |
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 3.2.2 does not restrict access to run-mpe.php, which allows remote attackers to run the Maintenance Priority Engine and possibly cause a denial of service (resource consumption…
|
CWE-264 CWE-399
Permissions, Privileges, and Access Controls Resource Management Errors
|
CVE-2015-7371
|
2024-11-21 11:36 |
2015-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211980
|
- |
|
revive-adserver
|
revive_adserver
|
Multiple cross-site scripting (XSS) vulnerabilities in open-flash-chart.swf in Open Flash Chart 2, as used in the VideoAds plugin in Revive Adserver before 3.2.2 and CA Release Automation (formerly L…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7370
|
2024-11-21 11:36 |
2015-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|