|
270861
|
- |
|
siemens
|
homecontrol_for_room_automation
|
The Siemens HomeControl for Room Automation application before 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obt…
|
CWE-310
Cryptographic Issues
|
CVE-2015-3610
|
2024-11-21 11:29 |
2015-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270862
|
- |
|
foxitsoftware
|
enterprise_reader foxit_reader phantompdf
|
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via vectors related to digital signatures.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3633
|
2024-11-21 11:29 |
2015-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270863
|
- |
|
foxitsoftware
|
enterprise_reader phantompdf foxit_reader
|
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted GIF in a PDF file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3632
|
2024-11-21 11:29 |
2015-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270864
|
- |
|
alienvault
|
unified_security_management
|
The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a crafted plugin configuration file (.cfg).
|
CWE-94
Code Injection
|
CVE-2015-3446
|
2024-11-21 11:29 |
2015-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270865
|
- |
|
samsung
|
samsung_security_manager
|
Samsung Security Manager (SSM) before 1.31 allows remote attackers to execute arbitrary code by uploading a file with an HTTP (1) PUT or (2) MOVE request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3435
|
2024-11-21 11:29 |
2015-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270866
|
- |
|
elasticsearch
|
elasticsearch
|
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2015-3337
|
2024-11-21 11:29 |
2015-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270867
|
- |
|
hospira
|
lifecare_pcainfusion_firmware lifecare_pca3 lifecare_pca5
|
The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify the pump configuratio…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3459
|
2024-11-21 11:29 |
2015-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270868
|
- |
|
magento
|
magento
|
The fetchView function in the Mage_Core_Block_Template_Zend class in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 does not restrict the stream wrapper used in a templat…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3458
|
2024-11-21 11:29 |
2015-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270869
|
- |
|
magento
|
magento
|
Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote attackers to bypass authentication via the forwarded parameter.
|
CWE-287
Improper Authentication
|
CVE-2015-3457
|
2024-11-21 11:29 |
2015-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270870
|
- |
|
rest-client_project
|
rest-client
|
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.
|
CWE-200
Information Exposure
|
CVE-2015-3448
|
2024-11-21 11:29 |
2015-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|