|
266871
|
6.5 |
MEDIUM
Network
|
isc
|
bind
|
apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed …
|
CWE-20
Improper Input Validation
|
CVE-2015-8704
|
2024-11-21 11:38 |
2016-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266872
|
9.8 |
CRITICAL
Network
|
php
|
php
|
Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a …
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2015-8617
|
2024-11-21 11:38 |
2016-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266873
|
8.6 |
HIGH
Network
|
php
|
php
|
Use-after-free vulnerability in the Collator::sortWithSortKeys function in ext/intl/collator/collator_sort.c in PHP 7.x before 7.0.1 allows remote attackers to cause a denial of service (application …
|
NVD-CWE-Other
|
CVE-2015-8616
|
2024-11-21 11:38 |
2016-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266874
|
5.4 |
MEDIUM
Network
|
gajim
|
gajim
|
Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.
|
CWE-20
Improper Input Validation
|
CVE-2015-8688
|
2024-11-21 11:38 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266875
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr
|
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) external calendar url or (2) the ba…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8685
|
2024-11-21 11:38 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266876
|
6.2 |
MEDIUM
Local
|
huawei
|
s5300_firmware
|
Huawei S5300 Campus Series switches with software before V200R005SPH008 do not mask the password when uploading files, which allows physically proximate attackers to obtain sensitive password informa…
|
CWE-255
Credentials Management
|
CVE-2015-8675
|
2024-11-21 11:38 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266877
|
7.5 |
HIGH
Network
|
samsung
|
web_viewer
|
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows attackers to bypass filesystem encryption via XOR calculations.
|
CWE-310
Cryptographic Issues
|
CVE-2015-8281
|
2024-11-21 11:38 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266878
|
7.5 |
HIGH
Network
|
samsung
|
web_viewer
|
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to discover credentials by reading detailed error messages.
|
CWE-200
Information Exposure
|
CVE-2015-8280
|
2024-11-21 11:38 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266879
|
8.6 |
HIGH
Network
|
samsung
|
web_viewer
|
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to read arbitrary files via a request to an unspecified PHP script.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8279
|
2024-11-21 11:38 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266880
|
6.5 |
MEDIUM
Adjacent
|
sophos isc debian canonical
|
unified_threat_management_up2date dhcp debian_linux ubuntu_linux
|
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
|
CWE-20
Improper Input Validation
|
CVE-2015-8605
|
2024-11-21 11:38 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|