|
268731
|
7.5 |
HIGH
Network
|
hp
|
integrated_lights-out_firmware
|
A potential security vulnerability has been identified with HP Integrated Lights-Out 4 (iLO 4) firmware version 2.11 and later, but prior to version 2.30. The vulnerability could be exploited remotel…
|
NVD-CWE-noinfo
|
CVE-2015-5436
|
2024-11-21 11:33 |
2017-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268732
|
9.8 |
CRITICAL
Network
|
samsung
|
nt14u_firmware x14j_firmware x14h_firmware x12_firmware x10p_firmware m288ofw_firmware
|
The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, which makes it easier for remote attackers to obtain …
|
CWE-200
Information Exposure
|
CVE-2015-5729
|
2024-11-21 11:33 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268733
|
5.5 |
MEDIUM
Local
|
freebsd
|
freebsd
|
bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file.
|
CWE-200
Information Exposure
|
CVE-2015-5677
|
2024-11-21 11:33 |
2017-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268734
|
9.8 |
CRITICAL
Network
|
misp-project
|
malware_information_sharing_platform
|
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_…
|
CWE-94
Code Injection
|
CVE-2015-5721
|
2024-11-21 11:33 |
2016-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268735
|
6.1 |
MEDIUM
Network
|
misp-project
|
malware_information_sharing_platform
|
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5720
|
2024-11-21 11:33 |
2016-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268736
|
9.8 |
CRITICAL
Network
|
misp-project
|
malware_information_sharing_platform
|
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact a…
|
NVD-CWE-noinfo
|
CVE-2015-5719
|
2024-11-21 11:33 |
2016-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268737
|
7.5 |
HIGH
Network
|
marvell f5
|
software_development_kit traffix_signaling_delivery_controller
|
The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for rem…
|
CWE-200
Information Exposure
|
CVE-2015-5738
|
2024-11-21 11:33 |
2016-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268738
|
6.1 |
MEDIUM
Network
|
qnap
|
qts
|
Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5664
|
2024-11-21 11:33 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268739
|
7.8 |
HIGH
Local
|
zend debian doctrine-project
|
zend-cache debian_linux object_relational_mapper doctrinemongodbbundle zend_framework common annotations mongodb-odm cache zf-apigility-doctrine
|
Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5723
|
2024-11-21 11:33 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268740
|
4.3 |
MEDIUM
Network
|
wordpress
|
wordpress
|
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arra…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5715
|
2024-11-21 11:33 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|