|
211341
|
5.3 |
MEDIUM
Network
|
arc_project
|
arc
|
ARC 5.21q allows directory traversal via a full pathname in an archive file.
|
CWE-22
Path Traversal
|
CVE-2015-9275
|
2024-11-21 11:40 |
2019-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211342
|
6.5 |
MEDIUM
Network
|
harfbuzz_project
|
harfbuzz
|
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-t…
|
CWE-125
Out-of-bounds Read
|
CVE-2015-9274
|
2024-11-21 11:40 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211343
|
6.1 |
MEDIUM
Network
|
wp-slimstat
|
slimstat_analytics
|
The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via a field associated with JavaScript-based Referer tracking.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9273
|
2024-11-21 11:40 |
2018-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211344
|
9.8 |
CRITICAL
Network
|
videowhisper
|
video_presentation
|
The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four charact…
|
CWE-94
Code Injection
|
CVE-2015-9272
|
2024-11-21 11:40 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211345
|
9.8 |
CRITICAL
Network
|
videowhisper
|
video_conference
|
The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-9271
|
2024-11-21 11:40 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211346
|
6.1 |
MEDIUM
Network
|
theholidaycalendar
|
holiday_calendar
|
XSS exists in the the-holiday-calendar plugin before 1.11.3 for WordPress via the thc-month parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9270
|
2024-11-21 11:40 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211347
|
7.5 |
HIGH
Network
|
wpmobilepack
|
wordpress_mobile_pack
|
The export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 2015-06-03 for WordPress allows remote attackers to obtain sensitive information because the content of a…
|
CWE-200
Information Exposure
|
CVE-2015-9269
|
2024-11-21 11:40 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211348
|
7.8 |
HIGH
Local
|
nullsoft debian
|
nullsoft_scriptable_install_system debian_linux
|
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the depend…
|
CWE-20
Improper Input Validation
|
CVE-2015-9268
|
2024-11-21 11:40 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211349
|
5.5 |
MEDIUM
Local
|
nullsoft debian
|
nullsoft_scriptable_install_system debian_linux
|
Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or th…
|
CWE-269
Improper Privilege Management
|
CVE-2015-9267
|
2024-11-21 11:40 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211350
|
9.8 |
CRITICAL
Network
|
ui ubnt
|
airmax_ac_firmware airmax_m_xm_firmware airmax_m_xw_firmware airmax_m_ti_firmware airgateway_firmware airfiber_af24_firmware airfiber_af24hd_firmware af5x_firmware af5_firmwar…
|
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory t…
|
CWE-22
Path Traversal
|
CVE-2015-9266
|
2024-11-21 11:40 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|