|
212361
|
6.8 |
MEDIUM
Adjacent
|
mediabridge
|
medialink_mwn-wapr300n_firmware
|
The web management interface on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 has a default password of admin for the admin account and a default password of password for the media…
|
CWE-255
Credentials Management
|
CVE-2015-5994
|
2024-11-21 11:34 |
2015-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212362
|
6.9 |
MEDIUM
Network
|
progress
|
whatsup_gold
|
Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to inject arbitrary web script or HTML via (1) an SNMP OID object, (2) an SNMP trap mes…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6005
|
2024-11-21 11:34 |
2015-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212363
|
6.5 |
MEDIUM
Network
|
progress
|
whatsup_gold
|
Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the UniqueID (aka sUniqueID) parameter to WrFreeFormText.a…
|
CWE-89
SQL Injection
|
CVE-2015-6004
|
2024-11-21 11:34 |
2015-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212364
|
5.9 |
MEDIUM
Network
|
cisco
|
jabber
|
Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSC…
|
CWE-200
Information Exposure
|
CVE-2015-6409
|
2024-11-21 11:34 |
2015-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212365
|
6.5 |
MEDIUM
Adjacent
|
cisco
|
ios_xe
|
Cisco IOS XE 16.1.1 allows remote attackers to cause a denial of service (device reload) via a packet with the 00-00-00-00-00-00 source MAC address, aka Bug ID CSCux48405.
|
CWE-399
Resource Management Errors
|
CVE-2015-6431
|
2024-11-21 11:34 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212366
|
- |
|
cisco
|
ios ios_xe
|
The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection termination) via a crafted IKEv1 packet to a…
|
CWE-19
Data Processing Errors
|
CVE-2015-6429
|
2024-11-21 11:34 |
2015-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212367
|
- |
|
cisco
|
dpq3925_8x4_docsis_3.0_wireless_residential_gateway_with_embedded_digital_voice_adapter
|
Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958.
|
CWE-200
Information Exposure
|
CVE-2015-6428
|
2024-11-21 11:34 |
2015-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212368
|
- |
|
cisco
|
firesight_system_software
|
Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka …
|
CWE-254
7PK - Security Features
|
CVE-2015-6427
|
2024-11-21 11:34 |
2015-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212369
|
- |
|
cisco
|
prime_network_services_controller
|
Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitrary commands via additional parameters to an unspecified command, aka Bug ID CS…
|
CWE-20
Improper Input Validation
|
CVE-2015-6426
|
2024-11-21 11:34 |
2015-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212370
|
- |
|
cisco
|
application_policy_infrastructure_controller
|
The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspeci…
|
CWE-255
Credentials Management
|
CVE-2015-6424
|
2024-11-21 11:34 |
2015-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|