|
267151
|
4.3 |
MEDIUM
Network
|
drupal
|
drupal
|
The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and …
|
CWE-200
Information Exposure
|
CVE-2015-7880
|
2024-11-21 11:37 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267152
|
5.4 |
MEDIUM
Network
|
stickynote_project
|
stickynote
|
Cross-site scripting (XSS) vulnerability in the Stickynote module 7.x before 7.x-1.3 for Drupal allows remote authenticated users with permission to create or edit a stickynote to inject arbitrary we…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7879
|
2024-11-21 11:37 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267153
|
9.8 |
CRITICAL
Network
|
user_dashboard_project
|
user_dashboard
|
Multiple SQL injection vulnerabilities in the User Dashboard module 7.x before 7.x-1.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2015-7877
|
2024-11-21 11:37 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267154
|
5.3 |
MEDIUM
Network
|
qt
|
qtwebkit
|
qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db.
|
CWE-200
Information Exposure
|
CVE-2015-8079
|
2024-11-21 11:37 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267155
|
5.4 |
MEDIUM
Network
|
centreon
|
centreon
|
Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).
|
CWE-79
Cross-site Scripting
|
CVE-2015-7672
|
2024-11-21 11:37 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267156
|
9.8 |
CRITICAL
Network
|
netapp
|
data_ontap
|
NetApp Data ONTAP before 8.2.4, when operating in 7-Mode, allows remote attackers to bypass authentication and (1) obtain sensitive information from or (2) modify volumes via vectors related to UTF-8…
|
CWE-287
Improper Authentication
|
CVE-2015-7746
|
2024-11-21 11:37 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267157
|
6.1 |
MEDIUM
Network
|
atutor
|
atutor
|
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the h parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7711
|
2024-11-21 11:37 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267158
|
9.8 |
CRITICAL
Network
|
pngcrush_project
|
pngcrush
|
Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.
|
CWE-415
Double Free
|
CVE-2015-7700
|
2024-11-21 11:37 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267159
|
6.5 |
MEDIUM
Network
|
samsung
|
samsung_mobile
|
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7896
|
2024-11-21 11:37 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267160
|
7.5 |
HIGH
Network
|
spi-inc
|
ganeti
|
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.…
|
CWE-200
Information Exposure
|
CVE-2015-7945
|
2024-11-21 11:37 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|