|
267581
|
4.2 |
MEDIUM
Physics
|
samsung seagate
|
850_pro_firmware pm851_firmware st500lt015_firmware st500lt025_firmware
|
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS…
|
CWE-254
7PK - Security Features
|
CVE-2015-7267
|
2024-11-21 11:36 |
2017-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267582
|
9.8 |
CRITICAL
Network
|
redhat
|
jboss_operations_network jboss_a-mq jboss_enterprise_application_platform jboss_bpm_suite jboss_enterprise_brms_platform openshift jboss_fuse subscription_asset_manager jboss_…
|
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2015-7501
|
2024-11-21 11:36 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267583
|
7.8 |
HIGH
Local
|
sos_project canonical redhat
|
sos ubuntu_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterprise_linux_server_eus
|
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by so…
|
CWE-59
Link Following
|
CVE-2015-7529
|
2024-11-21 11:36 |
2017-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267584
|
6.0 |
MEDIUM
Local
|
qemu
|
qemu
|
The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by leveragin…
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-7549
|
2024-11-21 11:36 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267585
|
8.8 |
HIGH
Local
|
qemu xen debian
|
qemu xen debian_linux
|
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via …
|
CWE-787
Out-of-bounds Write
|
CVE-2015-7504
|
2024-11-21 11:36 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267586
|
7.5 |
HIGH
Network
|
zend
|
zend_framework
|
Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.
|
CWE-320
Key Management Errors
|
CVE-2015-7503
|
2024-11-21 11:36 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267587
|
7.5 |
HIGH
Network
|
nodejs
|
node.js
|
Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-7384
|
2024-11-21 11:36 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267588
|
7.8 |
HIGH
Local
|
ciphershed idrix truecrypt
|
ciphershed veracrypt truecrypt
|
The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation leve…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7359
|
2024-11-21 11:36 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267589
|
7.8 |
HIGH
Local
|
ciphershed idrix truecrypt
|
ciphershed veracrypt truecrypt
|
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7358
|
2024-11-21 11:36 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267590
|
6.1 |
MEDIUM
Network
|
udesign_project
|
udesign
|
Cross-site scripting (XSS) vulnerability in the uDesign (aka U-Design) theme 2.3.0 before 2.7.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via a fragment identifier…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7357
|
2024-11-21 11:36 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|