|
271071
|
- |
|
mobile_devices
|
c4_obd-ii_dongle_firmware
|
Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, do not validate firmware updates, which allows remote attackers to execute arbit…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2015-2908
|
2024-11-21 11:28 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271072
|
- |
|
mobile_devices
|
c4_obd-ii_dongle_firmware
|
Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, have hardcoded SSH credentials, which makes it easier for remote attackers to ob…
|
NVD-CWE-Other
|
CVE-2015-2907
|
2024-11-21 11:28 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271073
|
- |
|
mobile_devices
|
c4_obd-ii_dongle_firmware
|
Mobile Devices (aka MDI) C4 OBD-II dongles with firmware 2.x and 3.4.x, as used in Metromile Pulse and other products, store SSH private keys that are the same across different customers' installatio…
|
NVD-CWE-Other
|
CVE-2015-2906
|
2024-11-21 11:28 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271074
|
- |
|
actiontec
|
_ncs01_firmware
|
Cross-site request forgery (CSRF) vulnerability on Actiontec GT784WN modems with firmware before NCS01-1.0.13 allows remote attackers to hijack the authentication or intranet connectivity of arbitrar…
|
CWE-352
Origin Validation Error
|
CVE-2015-2905
|
2024-11-21 11:28 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271075
|
- |
|
actiontec
|
_ncs01_firmware
|
Actiontec GT784WN modems with firmware before NCS01-1.0.13 have hardcoded credentials, which makes it easier for remote attackers to obtain root access by connecting to the web administration interfa…
|
NVD-CWE-Other
|
CVE-2015-2904
|
2024-11-21 11:28 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271076
|
- |
|
trendmicro
|
deep_discovery_inspector
|
Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions a…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2015-2873
|
2024-11-21 11:28 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271077
|
- |
|
trendmicro
|
deep_discovery_inspector
|
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x befor…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2872
|
2024-11-21 11:28 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271078
|
- |
|
php_kobo
|
photo_gallery_cms_free
|
Cross-site request forgery (CSRF) vulnerability in admin.php in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote attackers to hijack the authentica…
|
CWE-352
Origin Validation Error
|
CVE-2015-2983
|
2024-11-21 11:28 |
2015-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271079
|
- |
|
php_kobo
|
photo_gallery_cms_free
|
Cross-site scripting (XSS) vulnerability in jquery.lightbox-0.5.min.js in PHP Kobo Photo Gallery CMS for PC, smartphone and feature phone 1.0.1 Free and earlier allows remote authenticated users to i…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2982
|
2024-11-21 11:28 |
2015-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271080
|
- |
|
iodata
|
wn-g54\/r2_firmware
|
I-O DATA DEVICE WN-G54/R2 routers with firmware before 1.03 and NP-BBRS routers allow remote attackers to cause a denial of service (SSDP reflection) via UPnP requests.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2984
|
2024-11-21 11:28 |
2015-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|