|
267751
|
7.8 |
HIGH
Local
|
sos_project canonical redhat
|
sos ubuntu_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterprise_linux_server_eus
|
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by so…
|
CWE-59
Link Following
|
CVE-2015-7529
|
2024-11-21 11:36 |
2017-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267752
|
6.0 |
MEDIUM
Local
|
qemu
|
qemu
|
The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by leveragin…
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-7549
|
2024-11-21 11:36 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267753
|
8.8 |
HIGH
Local
|
qemu xen debian
|
qemu xen debian_linux
|
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via …
|
CWE-787
Out-of-bounds Write
|
CVE-2015-7504
|
2024-11-21 11:36 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267754
|
7.5 |
HIGH
Network
|
zend
|
zend_framework
|
Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.
|
CWE-320
Key Management Errors
|
CVE-2015-7503
|
2024-11-21 11:36 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267755
|
7.5 |
HIGH
Network
|
nodejs
|
node.js
|
Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-7384
|
2024-11-21 11:36 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267756
|
7.8 |
HIGH
Local
|
ciphershed idrix truecrypt
|
ciphershed veracrypt truecrypt
|
The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation leve…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7359
|
2024-11-21 11:36 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267757
|
7.8 |
HIGH
Local
|
ciphershed idrix truecrypt
|
ciphershed veracrypt truecrypt
|
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7358
|
2024-11-21 11:36 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267758
|
6.1 |
MEDIUM
Network
|
udesign_project
|
udesign
|
Cross-site scripting (XSS) vulnerability in the uDesign (aka U-Design) theme 2.3.0 before 2.7.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via a fragment identifier…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7357
|
2024-11-21 11:36 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267759
|
6.1 |
MEDIUM
Network
|
vasco
|
digipass
|
Cross-site scripting (XSS) vulnerability in the sample feedback.inc file in VASCO DIGIPASS authentication plug-in for Citrix Web Interface allows remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7349
|
2024-11-21 11:36 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267760
|
5.9 |
MEDIUM
Network
|
zyxel
|
nwa1100-n_firmware nwa1100-nh_firmware nwa1121-ni_firmware nwa1123-ac_firmware nwa1123-ni_firmware p-660hn-51_firmware p-663hn-51_firmware vmg1312-b10a_firmware vmg1312-b30a_f…
|
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-…
|
CWE-310
Cryptographic Issues
|
CVE-2015-7256
|
2024-11-21 11:36 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|