|
266891
|
8.8 |
HIGH
Network
|
axis
|
network_camera_firmware
|
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_…
|
CWE-77
Command Injection
|
CVE-2015-8257
|
2024-11-21 11:38 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266892
|
7.8 |
HIGH
Local
|
lenovo
|
lenovo_system_update
|
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8110
|
2024-11-21 11:38 |
2017-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266893
|
7.0 |
HIGH
Local
|
lenovo
|
lenovo_system_update
|
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowl…
|
CWE-255
Credentials Management
|
CVE-2015-8109
|
2024-11-21 11:38 |
2017-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266894
|
7.5 |
HIGH
Network
|
quickheal
|
total_security
|
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8285
|
2024-11-21 11:38 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266895
|
6.1 |
MEDIUM
Network
|
axis
|
network_camera_firmware
|
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
|
CWE-79
Cross-site Scripting
|
CVE-2015-8256
|
2024-11-21 11:38 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266896
|
8.0 |
HIGH
Network
|
bitrix_project
|
bitrix
|
Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) xls_profile parameter to adm…
|
CWE-89
SQL Injection
|
CVE-2015-8356
|
2024-11-21 11:38 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266897
|
7.5 |
HIGH
Network
|
qemu debian
|
qemu debian_linux
|
The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash).
|
CWE-787
Out-of-bounds Write
|
CVE-2015-8619
|
2024-11-21 11:38 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266898
|
7.7 |
HIGH
Network
|
qemu canonical debian suse opensuse fedoraproject
|
qemu ubuntu_linux debian_linux linux_enterprise_server linux_enterprise_desktop linux_enterprise_software_development_kit linux_enterprise_debuginfo leap opensuse fedora
|
Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2015-8567
|
2024-11-21 11:38 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266899
|
6.5 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash and infinite loop) via vectors involving the command block list.
|
CWE-399
Resource Management Errors
|
CVE-2015-8345
|
2024-11-21 11:38 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266900
|
8.8 |
HIGH
Network
|
seawell_networks
|
spectrum_sdc
|
SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
|
CWE-284
Improper Access Control
|
CVE-2015-8284
|
2024-11-21 11:38 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|