|
267631
|
7.8 |
HIGH
Local
|
dell
|
integrated_remote_access_controller_firmware
|
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.
|
CWE-22
Path Traversal
|
CVE-2015-7270
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267632
|
7.5 |
HIGH
Network
|
proxygen_project
|
proxygen
|
Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.
|
CWE-284
Improper Access Control
|
CVE-2015-7265
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267633
|
9.8 |
CRITICAL
Network
|
proxygen_project
|
proxygen
|
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks.
|
CWE-74
Injection
|
CVE-2015-7264
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267634
|
7.5 |
HIGH
Network
|
proxygen_project
|
proxygen
|
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value.
|
CWE-284
Improper Access Control
|
CVE-2015-7263
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267635
|
7.8 |
HIGH
Local
|
vertiv
|
liebert_multilink_automated_shutdown
|
Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable file.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7260
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267636
|
5.5 |
MEDIUM
Local
|
libtiff
|
libtiff
|
LibTIFF allows remote attackers to cause a denial of service (memory consumption and crash) via a crafted tiff file.
|
CWE-399
Resource Management Errors
|
CVE-2015-7313
|
2024-11-21 11:36 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267637
|
2.8 |
LOW
Local
|
ibm
|
cloud_orchestrator smartcloud_orchestrator
|
A vulnerability has been identified in IBM Cloud Orchestrator services/[action]/launch API. An authenticated domain admin user might modify cross domain resources via a /services/[action]/launch API …
|
CWE-284
Improper Access Control
|
CVE-2015-7494
|
2024-11-21 11:36 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267638
|
4.7 |
MEDIUM
Local
|
ibm
|
infosphere_information_server
|
IBM InfoSphere Information Server could allow a local user under special circumstances to execute commands during installation processes that could expose sensitive information.
|
CWE-200
Information Exposure
|
CVE-2015-7493
|
2024-11-21 11:36 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267639
|
4.4 |
MEDIUM
Local
|
ibm
|
websphere_extreme_scale
|
IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory instead of being overwritten which could allow a local user with administrator pri…
|
CWE-200
Information Exposure
|
CVE-2015-7418
|
2024-11-21 11:36 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267640
|
6.6 |
MEDIUM
Network
|
puppetlabs
|
mcollective-puppet-agent
|
The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --server argument.
|
CWE-254
7PK - Security Features
|
CVE-2015-7331
|
2024-11-21 11:36 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|