|
211741
|
6.6 |
MEDIUM
Local
|
apple
|
quicktime
|
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerabili…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7085
|
2024-11-21 11:36 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211742
|
10.0 |
CRITICAL
Network
|
colorscore_project
|
colorscore
|
The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary code via shell metachar…
|
CWE-77
Command Injection
|
CVE-2015-7541
|
2024-11-21 11:36 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211743
|
9.0 |
CRITICAL
Network
|
qemu redhat debian oracle
|
qemu enterprise_linux_eus enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation openstack virtualization debian_linux linux
|
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary …
|
CWE-120
Classic Buffer Overflow
|
CVE-2015-7512
|
2024-11-21 11:36 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211744
|
9.8 |
CRITICAL
Network
|
libtiff
|
libtiff
|
The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field da…
|
CWE-254
7PK - Security Features
|
CVE-2015-7554
|
2024-11-21 11:36 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211745
|
3.7 |
LOW
Network
|
phusionpassenger
|
phusion_passenger
|
agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote a…
|
CWE-20
Improper Input Validation
|
CVE-2015-7519
|
2024-11-21 11:36 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211746
|
7.8 |
HIGH
Local
|
fortinet
|
forticlient
|
Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable and executable, allows local users to gain privileges via the helper/subroc set…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7362
|
2024-11-21 11:36 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211747
|
4.7 |
MEDIUM
Local
|
puppet
|
puppet_enterprise
|
Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permissions for the private key of the Certification Authority (CA) certificate during th…
|
CWE-200
Information Exposure
|
CVE-2015-7328
|
2024-11-21 11:36 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211748
|
4.7 |
MEDIUM
Local
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive cleartext web-services information by leveraging database access.
|
CWE-200
Information Exposure
|
CVE-2015-7438
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211749
|
4.3 |
MEDIUM
Network
|
ibm
|
maximo_for_transportation maximo_for_utilities maximo_asset_management smartcloud_control_desk maximo_for_life_sciences maximo_asset_management_essentials maximo_for_nuclear_power
|
IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow r…
|
CWE-200
Information Exposure
|
CVE-2015-7452
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211750
|
9.8 |
CRITICAL
Network
|
ibm
|
sterling_integrator tivoli_common_reporting sterling_b2b_integrator websphere_application_server watson_content_analytics watson_explorer_analytical_components watson_explorer_annot…
|
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a craf…
|
NVD-CWE-noinfo
|
CVE-2015-7450
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|