|
271581
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_desktop_central
|
Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2560
|
2024-11-21 11:27 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271582
|
6.1 |
MEDIUM
Network
|
digium
|
addons_module
|
Multiple cross-site scripting (XSS) vulnerabilities in views/add-license-form.php in the Digium Addons module (digiumaddoninstaller) before 2.11.0.7 for FreePBX allow remote attackers to inject arbit…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2690
|
2024-11-21 11:27 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271583
|
8.8 |
HIGH
Network
|
airlink101
|
skyipcam1620w_wireless_n_mpeg4_3gpp_firmware
|
snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote authenticated users to execute arbitrary OS commands v…
|
CWE-78
OS Command
|
CVE-2015-2280
|
2024-11-21 11:27 |
2017-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271584
|
9.8 |
CRITICAL
Network
|
airlive
|
bu-2015_firmware bu-3026_firmware md-3025_firmware
|
cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows remote attackers to execute arbitrary OS commands via shell metacharacters aft…
|
CWE-78
OS Command
|
CVE-2015-2279
|
2024-11-21 11:27 |
2017-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271585
|
7.5 |
HIGH
Network
|
huawei
|
p7-l09_firmware
|
Huawei Ascend P7 allows remote attackers to cause a denial of service (phone process crash).
|
CWE-20
Improper Input Validation
|
CVE-2015-2245
|
2024-11-21 11:27 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271586
|
10.0 |
CRITICAL
Network
|
adblock
|
adblock
|
AdBlock before 2.21 allows remote attackers to block arbitrary resources on arbitrary websites and to disable arbitrary blocking filters.
|
CWE-284
Improper Access Control
|
CVE-2015-2692
|
2024-11-21 11:27 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271587
|
5.9 |
MEDIUM
Network
|
huawei
|
ar1220_firmware
|
Huawei AR1220 routers with software before V200R005SPH006 allow remote attackers to cause a denial of service (board reset) via vectors involving a large amount of traffic from the GE port to the FE …
|
CWE-19
Data Processing Errors
|
CVE-2015-2255
|
2024-11-21 11:27 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271588
|
5.0 |
MEDIUM
Local
|
huawei
|
oceanstor_uds_firmware
|
The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document.
|
CWE-200
Information Exposure
|
CVE-2015-2253
|
2024-11-21 11:27 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271589
|
8.8 |
HIGH
Network
|
huawei
|
oceanstor_uds_firmware
|
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a crafted UDS patch with shell scripts.
|
CWE-94
Code Injection
|
CVE-2015-2252
|
2024-11-21 11:27 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271590
|
7.5 |
HIGH
Network
|
huawei
|
oceanstor_uds_firmware
|
The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information via a crafted UDS patch with JavaScript.
|
CWE-200
Information Exposure
|
CVE-2015-2251
|
2024-11-21 11:27 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|