|
270331
|
- |
|
cisco
|
unified_presence_server
|
Cross-site scripting (XSS) vulnerability in Cisco Unified Presence Server 9.1(1) allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuq03773.
|
CWE-79
Cross-site Scripting
|
CVE-2015-4220
|
2024-11-21 11:30 |
2015-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270332
|
- |
|
ruby-lang rubygems oracle redhat
|
ruby rubygems solaris enterprise_linux
|
RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests t…
|
CWE-254
7PK - Security Features
|
CVE-2015-3900
|
2024-11-21 11:30 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270333
|
- |
|
cisco
|
secure_access_control_system identity_services_engine_software
|
Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows…
|
CWE-264 CWE-200
Permissions, Privileges, and Access Controls Information Exposure
|
CVE-2015-4219
|
2024-11-21 11:30 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270334
|
- |
|
cisco
|
jabber
|
The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information via a crafted value in a GET request, aka Bug IDs…
|
CWE-200
Information Exposure
|
CVE-2015-4218
|
2024-11-21 11:30 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270335
|
- |
|
cisco
|
wireless_lan_controller_software
|
Cisco Wireless LAN Controller (WLC) devices with software 7.5(102.0) and 7.6(1.62) allow remote attackers to cause a denial of service (device crash) by triggering an exception during attempted forwa…
|
CWE-399
Resource Management Errors
|
CVE-2015-4215
|
2024-11-21 11:30 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270336
|
- |
|
cisco
|
unified_meetingplace
|
Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) allows remote authenticated users to discover cleartext passwords by reading HTML source code, aka Bug ID CSCuu33050.
|
CWE-200
Information Exposure
|
CVE-2015-4214
|
2024-11-21 11:30 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270337
|
- |
|
cisco
|
nx-os
|
Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption mechanism, aka Bug ID CSCuu84391.
|
CWE-200
Information Exposure
|
CVE-2015-4213
|
2024-11-21 11:30 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270338
|
- |
|
cisco
|
webex_meeting_center
|
Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by discovering credentials, aka Bug ID CSCut17466.
|
CWE-200
Information Exposure
|
CVE-2015-4212
|
2024-11-21 11:30 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270339
|
- |
|
cisco
|
anyconnect_secure_mobility_client
|
Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCus65862.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-4211
|
2024-11-21 11:30 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270340
|
- |
|
cisco
|
webex_meeting_center
|
Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive information or conduct SQL injection attacks via vectors i…
|
CWE-200 CWE-89
Information Exposure SQL Injection
|
CVE-2015-4208
|
2024-11-21 11:30 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|