|
212221
|
- |
|
ffmpeg canonical
|
ffmpeg ubuntu_linux
|
The ff_sbr_apply function in libavcodec/aacsbr.c in FFmpeg before 2.7.2 does not check for a matching AAC frame syntax element before proceeding with Spectral Band Replication calculations, which all…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6820
|
2024-11-21 11:35 |
2015-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212222
|
- |
|
ffmpeg
|
ffmpeg
|
Multiple integer underflows in the ff_mjpeg_decode_frame function in libavcodec/mjpegdec.c in FFmpeg before 2.7.2 allow remote attackers to cause a denial of service (out-of-bounds array access) or p…
|
CWE-189
Numeric Errors
|
CVE-2015-6819
|
2024-11-21 11:35 |
2015-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212223
|
- |
|
ffmpeg canonical
|
ffmpeg ubuntu_linux
|
The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does not enforce uniqueness of the IHDR (aka image header) chunk in a PNG image, which allows remote attackers to cause a …
|
CWE-17
Code
|
CVE-2015-6818
|
2024-11-21 11:35 |
2015-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212224
|
- |
|
invisioncommunity
|
invision_power_board
|
Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause a denial of service (loop and memory consumption) via a cr…
|
CWE-399
Resource Management Errors
|
CVE-2015-6812
|
2024-11-21 11:35 |
2015-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212225
|
- |
|
cyberoam
|
cyberoamos
|
SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlier allows remote attackers to execute arbitrary SQL commands via the username pa…
|
CWE-89
SQL Injection
|
CVE-2015-6811
|
2024-11-21 11:35 |
2015-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212226
|
- |
|
invisionpower
|
invision_power_board
|
Cross-site scripting (XSS) vulnerability in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) 4.x before 4.0.12.1 allows remote authenticated users to inject…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6810
|
2024-11-21 11:35 |
2015-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212227
|
- |
|
bedita
|
bedita
|
Multiple cross-site scripting (XSS) vulnerabilities in BEdita before 3.6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cfg[projectName] parameter to index.php/admin/save…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6809
|
2024-11-21 11:35 |
2015-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212228
|
- |
|
getlevelten
|
spotlight
|
Cross-site scripting (XSS) vulnerability in the Spotlight module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML vi…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6808
|
2024-11-21 11:35 |
2015-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212229
|
- |
|
mass_contact_project
|
mass_contact
|
Cross-site scripting (XSS) vulnerability in the Mass Contact module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer mass contact" p…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6807
|
2024-11-21 11:35 |
2015-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212230
|
- |
|
google
|
chrome
|
Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app's window after navigation away from the installation site, which might make it easier for remote attackers to spoof …
|
CWE-254
7PK - Security Features
|
CVE-2015-6583
|
2024-11-21 11:35 |
2015-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|