|
212431
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which allows local users to cause a denial of service (…
|
CWE-20
Improper Input Validation
|
CVE-2015-8019
|
2024-11-21 11:37 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212432
|
5.5 |
MEDIUM
Local
|
optipng_project canonical
|
optipng ubuntu_linux
|
gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7802
|
2024-11-21 11:37 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212433
|
8.8 |
HIGH
Network
|
optipng_project canonical
|
optipng ubuntu_linux
|
Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file.
|
NVD-CWE-Other
|
CVE-2015-7801
|
2024-11-21 11:37 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212434
|
5.4 |
MEDIUM
Network
|
ipswitch
|
moveit_dmz
|
Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uplo…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7676
|
2024-11-21 11:37 |
2016-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212435
|
8.1 |
HIGH
Network
|
citrix
|
command_center
|
Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbi…
|
CWE-89
SQL Injection
|
CVE-2015-7999
|
2024-11-21 11:37 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212436
|
7.5 |
HIGH
Network
|
redislabs debian opensuse redhat
|
redis debian_linux leap opensuse openstack
|
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to ca…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2015-8080
|
2024-11-21 11:37 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212437
|
4.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager big-ip_link_controller big-ip_analytics big-ip_edge_gateway big-ip_protocol_security_module big-ip_local_traffic_manager big-ip_wan_optimization_manager…
|
Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 bef…
|
CWE-284
Improper Access Control
|
CVE-2015-8021
|
2024-11-21 11:37 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212438
|
9.1 |
CRITICAL
Network
|
schneider-electric
|
proface_gp-pro_ex_pfxexedls proface_gp-pro_ex_pfxexedv proface_gp-pro_ex_ex-ed proface_gp-pro_ex_pfxexgrpls
|
The FTP server in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 has hardcoded credentials, which makes it easier for re…
|
CWE-255
Credentials Management
|
CVE-2015-7921
|
2024-11-21 11:37 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212439
|
6.3 |
MEDIUM
Network
|
basercms
|
basercms
|
baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2015-7769
|
2024-11-21 11:37 |
2016-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212440
|
6.1 |
MEDIUM
Network
|
cybozu
|
office
|
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than C…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7798
|
2024-11-21 11:37 |
2016-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|