|
266881
|
7.3 |
HIGH
Network
|
canonical perl debian
|
ubuntu_linux pathtools debian_linux
|
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to byp…
|
CWE-20
Improper Input Validation
|
CVE-2015-8607
|
2024-11-21 11:38 |
2016-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266882
|
7.4 |
HIGH
Network
|
fedoraproject openstack
|
fedora swift3
|
Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.
|
CWE-20
Improper Input Validation
|
CVE-2015-8466
|
2024-11-21 11:38 |
2016-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266883
|
6.8 |
MEDIUM
Physics
|
huawei
|
te50 te40 te60 te30 te60_firmware
|
Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 do not require entry of the old password when changing the password for the Debug acco…
|
CWE-255
Credentials Management
|
CVE-2015-8673
|
2024-11-21 11:38 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266884
|
5.3 |
MEDIUM
Network
|
huawei
|
te60_firmware
|
The presentation transmission permission management mechanism in Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 allows remote attacke…
|
CWE-19
Data Processing Errors
|
CVE-2015-8672
|
2024-11-21 11:38 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266885
|
9.8 |
CRITICAL
Network
|
f5
|
big-ip_domain_name_system big-ip_application_acceleration_manager big-ip_link_controller big-ip_policy_enforcement_manager big-ip_advanced_firewall_manager big-ip_local_traffic_manager…
|
BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, and PEM 12.0.0 before HF1 on the 2000, 4000, 5000, 7000, and 10000 platforms do not properly sync passwords with the Always-On Managem…
|
CWE-255
Credentials Management
|
CVE-2015-8611
|
2024-11-21 11:38 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266886
|
8.2 |
HIGH
Network
|
grassroots_dicom_project
|
grassroots_dicom
|
The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote attackers to obtain sensitive information from proces…
|
CWE-125
Out-of-bounds Read
|
CVE-2015-8397
|
2024-11-21 11:38 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266887
|
10.0 |
CRITICAL
Network
|
grassroots_dicom_project
|
grassroots_dicom
|
Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows attackers to execute arbit…
|
CWE-189
Numeric Errors
|
CVE-2015-8396
|
2024-11-21 11:38 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266888
|
10.0 |
CRITICAL
Network
|
apple nghttp2
|
mac_os_x watchos iphone_os nghttp2 tvos
|
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8659
|
2024-11-21 11:38 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266889
|
5.4 |
MEDIUM
Network
|
s9y
|
serendipity
|
Cross-site scripting (XSS) vulnerability in Serendipity before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the serendipity[entry_id] parameter in an "edit" admin action t…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8603
|
2024-11-21 11:38 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266890
|
7.4 |
HIGH
Network
|
fedoraproject shellinabox_project
|
fedora shellinabox
|
The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.
|
CWE-254
7PK - Security Features
|
CVE-2015-8400
|
2024-11-21 11:38 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|