|
270291
|
- |
|
ektron
|
ektron_content_management_system
|
Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.114) allow remote authenticated users t…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4427
|
2024-11-21 11:31 |
2015-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270292
|
- |
|
zohocorp
|
manageengine_netflow_analyzer
|
Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended…
|
CWE-284
Improper Access Control
|
CVE-2015-4418
|
2024-11-21 11:31 |
2015-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270293
|
9.8 |
CRITICAL
Network
|
gnu
|
coreutils
|
Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified othe…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2015-4042
|
2024-11-21 11:30 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270294
|
7.8 |
HIGH
Local
|
gnu
|
coreutils
|
The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, wh…
|
CWE-787
Out-of-bounds Write
|
CVE-2015-4041
|
2024-11-21 11:30 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270295
|
5.4 |
MEDIUM
Network
|
e-plugins
|
wp_membership
|
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4039
|
2024-11-21 11:30 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270296
|
9.8 |
CRITICAL
Network
|
codeigniter-restserver_project
|
codeigniter-restserver
|
CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.
|
CWE-611
XXE
|
CVE-2015-3907
|
2024-11-21 11:30 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270297
|
9.8 |
CRITICAL
Network
|
pifzer
|
plum_a\+_infusion_system_firmware plum_a\+3_infusion_system_firmware symbiq_infusion_system_firmware
|
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior accept drug libraries, firmware updates, pu…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2015-3956
|
2024-11-21 11:30 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270298
|
9.8 |
CRITICAL
Network
|
pifzer
|
plum_a\+_infusion_system_firmware plum_a\+3_infusion_system_firmware symbiq_infusion_system_firmware
|
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges …
|
CWE-285
Improper Authorization
|
CVE-2015-3954
|
2024-11-21 11:30 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270299
|
7.5 |
HIGH
Network
|
pifzer
|
plum_a\+_infusion_system_firmware plum_a\+3_infusion_system_firmware symbiq_infusion_system_firmware
|
Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. …
|
CWE-200
Information Exposure
|
CVE-2015-3952
|
2024-11-21 11:30 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270300
|
9.8 |
CRITICAL
Network
|
pifzer
|
plum_a\+_infusion_system_firmware plum_a\+3_infusion_system_firmware symbiq_infusion_system_firmware
|
Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2015-3953
|
2024-11-21 11:30 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|