|
277731
|
7.8 |
HIGH
Local
|
mobilis
|
mobiconnect
|
Untrusted search path vulnerability in ZTE Datacard MF19 0V1.0.0B04 allows local users to gain privilege by modifying the 'Ucell Internet' directory to reference a malicious mms_dll_r.dll or mediapla…
|
CWE-426
Untrusted Search Path
|
CVE-2015-0974
|
2024-11-21 11:24 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277732
|
7.5 |
HIGH
Network
|
oisf
|
libhtp
|
libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-0928
|
2024-11-21 11:24 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277733
|
9.8 |
CRITICAL
Network
|
unit4
|
teta_web
|
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id.
|
CWE-384
Session Fixation
|
CVE-2015-1174
|
2024-11-21 11:24 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277734
|
6.5 |
MEDIUM
Network
|
google debian
|
chrome debian_linux
|
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
|
CWE-415
Double Free
|
CVE-2015-1207
|
2024-11-21 11:24 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277735
|
9.8 |
CRITICAL
Network
|
ceragon
|
fibeair_ip-10_firmware
|
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
|
CWE-320
Key Management Errors
|
CVE-2015-0936
|
2024-11-21 11:24 |
2017-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277736
|
7.8 |
HIGH
Local
|
csv2wpec-coupon_project
|
csv2wpec-coupon
|
Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-1000013
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277737
|
7.5 |
HIGH
Network
|
mypixs_project
|
mypixs
|
Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin
|
CWE-200
Information Exposure
|
CVE-2015-1000012
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277738
|
9.8 |
CRITICAL
Network
|
dukapress_project
|
dukapress
|
Blind SQL Injection in wordpress plugin dukapress v2.5.9
|
CWE-89
SQL Injection
|
CVE-2015-1000011
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277739
|
7.5 |
HIGH
Network
|
simple-image-manipulator_project
|
simple-image-manipulator
|
Remote file download in simple-image-manipulator v1.0 wordpress plugin
|
CWE-284
Improper Access Control
|
CVE-2015-1000010
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277740
|
9.1 |
CRITICAL
Network
|
google-adsense-and-hotel-booking_project
|
google-adsense-and-hotel-booking
|
Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05
|
CWE-284
Improper Access Control
|
CVE-2015-1000009
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|