|
266771
|
7.3 |
HIGH
Local
|
fedoraproject fuseiso_project
|
fedora fuseiso
|
Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other imp…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8836
|
2024-11-21 11:39 |
2016-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266772
|
8.8 |
HIGH
Network
|
adobe
|
flash_player flash_player_desktop_runtime air_desktop_runtime air_sdk air_sdk_\&_compiler air
|
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR S…
|
CWE-416
Use After Free
|
CVE-2015-8822
|
2024-11-21 11:39 |
2016-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266773
|
8.8 |
HIGH
Network
|
adobe
|
flash_player flash_player_desktop_runtime air_desktop_runtime air_sdk air_sdk_\&_compiler air
|
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR S…
|
CWE-416
Use After Free
|
CVE-2015-8821
|
2024-11-21 11:39 |
2016-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266774
|
8.8 |
HIGH
Network
|
adobe
|
flash_player flash_player_desktop_runtime air_desktop_runtime air_sdk air_sdk_\&_compiler air
|
Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe …
|
CWE-787
Out-of-bounds Write
|
CVE-2015-8820
|
2024-11-21 11:39 |
2016-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266775
|
9.8 |
CRITICAL
Network
|
nettle_project canonical opensuse
|
nettle ubuntu_linux leap opensuse
|
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allo…
|
CWE-310
Cryptographic Issues
|
CVE-2015-8805
|
2024-11-21 11:39 |
2016-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266776
|
9.8 |
CRITICAL
Network
|
nettle_project canonical opensuse
|
nettle ubuntu_linux leap opensuse
|
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to…
|
CWE-310 CWE-254
Cryptographic Issues 7PK - Security Features
|
CVE-2015-8804
|
2024-11-21 11:39 |
2016-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266777
|
9.8 |
CRITICAL
Network
|
nettle_project canonical opensuse
|
nettle ubuntu_linux leap opensuse
|
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allo…
|
CWE-310 CWE-254
Cryptographic Issues 7PK - Security Features
|
CVE-2015-8803
|
2024-11-21 11:39 |
2016-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266778
|
6.1 |
MEDIUM
Network
|
apache
|
solr
|
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/plugins.js in the stats page in the Admin UI in Apache Solr before 5.3.1 allows remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8797
|
2024-11-21 11:39 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266779
|
6.1 |
MEDIUM
Network
|
apache
|
solr
|
Cross-site scripting (XSS) vulnerability in webapp/web/js/scripts/schema-browser.js in the Admin UI in Apache Solr before 5.3 allows remote attackers to inject arbitrary web script or HTML via a craf…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8796
|
2024-11-21 11:39 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266780
|
6.1 |
MEDIUM
Network
|
apache
|
solr
|
Multiple cross-site scripting (XSS) vulnerabilities in the Admin UI in Apache Solr before 5.1 allow remote attackers to inject arbitrary web script or HTML via crafted fields that are mishandled duri…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8795
|
2024-11-21 11:39 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|