|
212461
|
7.5 |
HIGH
Network
|
avira
|
avira_mobile_security
|
The Avira Mobile Security app before 1.5.11 for iOS sends sensitive login information in cleartext.
|
CWE-200
Information Exposure
|
CVE-2015-7732
|
2024-11-21 11:37 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212462
|
7.5 |
HIGH
Network
|
samsung
|
galaxy_s6_edge_firmware
|
Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via…
|
CWE-22
Path Traversal
|
CVE-2015-7888
|
2024-11-21 11:37 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212463
|
7.8 |
HIGH
Local
|
amd
|
fglrx-driver
|
AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723.
|
CWE-59
Link Following
|
CVE-2015-7724
|
2024-11-21 11:37 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212464
|
7.8 |
HIGH
Local
|
amd
|
fglrx-driver
|
AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
|
CWE-59
Link Following
|
CVE-2015-7723
|
2024-11-21 11:37 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212465
|
7.2 |
HIGH
Network
|
yeager
|
yeager_cms
|
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports via the dbhost parameter to libs/org/adodb…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2015-7570
|
2024-11-21 11:37 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212466
|
8.8 |
HIGH
Network
|
yeager
|
yeager_cms
|
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter.
|
CWE-89
SQL Injection
|
CVE-2015-7569
|
2024-11-21 11:37 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212467
|
9.8 |
CRITICAL
Network
|
yeager
|
yeager_cms
|
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.
|
CWE-89
SQL Injection
|
CVE-2015-7568
|
2024-11-21 11:37 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212468
|
5.5 |
MEDIUM
Local
|
huawei
|
p7_firmware p8_ale-ul00_firmware
|
Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B851 and P8 ALE-UL00 before ALE-UL00B211 allows local users to cause a denial of service (OS crash) via vectors involving an application th…
|
CWE-20
Improper Input Validation
|
CVE-2015-7740
|
2024-11-21 11:37 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212469
|
8.8 |
HIGH
Network
|
samsung
|
galaxy_s6
|
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.
|
CWE-20
Improper Input Validation
|
CVE-2015-7893
|
2024-11-21 11:37 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212470
|
9.8 |
CRITICAL
Network
|
botan_project
|
botan
|
botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as demonstrated by acc…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-7826
|
2024-11-21 11:37 |
2017-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|