|
271091
|
- |
|
sierrawireless
|
aleos
|
Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNE…
|
CWE-200
Information Exposure
|
CVE-2015-2897
|
2024-11-21 11:28 |
2015-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271092
|
6.0 |
MEDIUM
Local
|
dell
|
bios
|
The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a B…
|
NVD-CWE-noinfo
|
CVE-2015-2890
|
2024-11-21 11:28 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271093
|
- |
|
chiyu
|
bf-660c
|
Chiyu BF-660C fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) modify communication configuration settings via a request to net.htm, a different …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2871
|
2024-11-21 11:28 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271094
|
- |
|
chiyutw
|
bf-630 bf-630w bf-660c
|
Cross-site scripting (XSS) vulnerability on Chiyu BF-630, BF-630W, and BF-660C fingerprint access-control devices allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2870
|
2024-11-21 11:28 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271095
|
- |
|
webservice-dic
|
yoyaku
|
Webservice-DIC yoyaku_v41 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2015-2979
|
2024-11-21 11:28 |
2015-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271096
|
- |
|
webservice-dic
|
yoyaku
|
Webservice-DIC yoyaku_v41 allows remote attackers to bypass authentication and complete a conference-room reservation via unspecified vectors, as demonstrated by an "unintentional reservation."
|
CWE-287
Improper Authentication
|
CVE-2015-2978
|
2024-11-21 11:28 |
2015-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271097
|
- |
|
webservice-dic
|
yoyaku
|
Webservice-DIC yoyaku_v41 allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2015-2977
|
2024-11-21 11:28 |
2015-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271098
|
- |
|
lemon-s_php
|
gazou_bbs_plus
|
LEMON-S PHP Gazou BBS plus before 2.36 allows remote attackers to upload arbitrary HTML documents via vectors involving a crafted image file.
|
CWE-20
Improper Input Validation
|
CVE-2015-2974
|
2024-11-21 11:28 |
2015-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271099
|
- |
|
opensuse rubyonrails
|
opensuse rails
|
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service…
|
NVD-CWE-noinfo
|
CVE-2015-3227
|
2024-11-21 11:28 |
2015-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271100
|
- |
|
rubyonrails
|
ruby_on_rails rails
|
Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web scri…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3226
|
2024-11-21 11:28 |
2015-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|