|
268061
|
8.8 |
HIGH
Network
|
zimbra
|
zimbra_collaboration_server
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication of arbitrary users…
|
CWE-352
Origin Validation Error
|
CVE-2015-6541
|
2024-11-21 11:35 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268062
|
9.1 |
CRITICAL
Network
|
broadcom
|
single_sign-on
|
The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR5 allow remote attackers to cause a denial of serv…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2015-6854
|
2024-11-21 11:35 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268063
|
9.1 |
CRITICAL
Network
|
broadcom
|
single_sign-on
|
The Domino web agent in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, R12.5 before CR5, R12.51 before CR4, and R12.52 before SP1 CR3 allows remo…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2015-6853
|
2024-11-21 11:35 |
2016-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268064
|
5.3 |
MEDIUM
Network
|
schneider-electric
|
telvent_rtu_firmware
|
Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, al…
|
CWE-200
Information Exposure
|
CVE-2015-6485
|
2024-11-21 11:35 |
2016-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268065
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a crafted DTLS cookie in a ClientHello message.
|
CWE-399
Resource Management Errors
|
CVE-2015-6925
|
2024-11-21 11:35 |
2016-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268066
|
7.3 |
HIGH
Network
|
php
|
php
|
The SoapClient __call method in ext/soap/soap.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 does not properly manage headers, which allows remote attackers to execute arbitrary…
|
NVD-CWE-Other
|
CVE-2015-6836
|
2024-11-21 11:35 |
2016-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268067
|
7.5 |
HIGH
Network
|
php
|
php
|
Directory traversal vulnerability in the PharData class in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to write to arbitrary files via a .. (dot dot) in a …
|
CWE-22
Path Traversal
|
CVE-2015-6833
|
2024-11-21 11:35 |
2016-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268068
|
7.3 |
HIGH
Network
|
php
|
php
|
Use-after-free vulnerability in the SPL unserialize implementation in ext/spl/spl_array.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to execute arbitra…
|
NVD-CWE-Other
|
CVE-2015-6832
|
2024-11-21 11:35 |
2016-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268069
|
7.3 |
HIGH
Network
|
php debian
|
php debian_linux
|
Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObjec…
|
CWE-416
Use After Free
|
CVE-2015-6831
|
2024-11-21 11:35 |
2016-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268070
|
7.3 |
HIGH
Network
|
php
|
php
|
The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a crafted value in the third argument to the str_ireplac…
|
NVD-CWE-noinfo
|
CVE-2015-6527
|
2024-11-21 11:35 |
2016-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|