|
267771
|
4.7 |
MEDIUM
Local
|
redhat
|
enterprise_linux kernel-rt enterprise_mrg
|
Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by…
|
CWE-362
Race Condition
|
CVE-2015-7553
|
2024-11-21 11:36 |
2017-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267772
|
7.5 |
HIGH
Network
|
ldapauth-fork_project
|
ldapauth-fork
|
ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection attacks via a crafted username.
|
CWE-90
LDAP Injection
|
CVE-2015-7294
|
2024-11-21 11:36 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267773
|
9.8 |
CRITICAL
Network
|
sap
|
netweaver
|
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
|
CWE-611
XXE
|
CVE-2015-7241
|
2024-11-21 11:36 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267774
|
5.3 |
MEDIUM
Network
|
tinfoilsecurity
|
devise-two-factor
|
Tinfoil Devise-two-factor before 2.0.0 does not strictly follow section 5.2 of RFC 6238 and does not "burn" a successfully validated one-time password (aka OTP), which allows remote or physically pro…
|
CWE-254
7PK - Security Features
|
CVE-2015-7225
|
2024-11-21 11:36 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267775
|
9.8 |
CRITICAL
Network
|
labwebdesigns
|
double_opt-in_for_download
|
Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-…
|
CWE-89
SQL Injection
|
CVE-2015-7517
|
2024-11-21 11:36 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267776
|
7.5 |
HIGH
Network
|
zte
|
ox-330p_firmware zxhn_h108n_firmware w300v1.0.0s_zrd_tr1_d68_firmware hg110_firmware gan9.8t101a-b_firmware mf28g_firmware
|
ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials…
|
CWE-200
Information Exposure
|
CVE-2015-7255
|
2024-11-21 11:36 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267777
|
7.5 |
HIGH
Network
|
onosproject
|
onos
|
ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconnect) by sending two Ethernet frames with ether_type Jumbo Fr…
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-7516
|
2024-11-21 11:36 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267778
|
8.8 |
HIGH
Network
|
zte
|
zxv10_w300_firmware
|
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, which allows remote authenticated users to login t…
|
CWE-255
Credentials Management
|
CVE-2015-7259
|
2024-11-21 11:36 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267779
|
8.8 |
HIGH
Network
|
zte
|
zxv10_w300_firmware
|
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.
|
CWE-255
Credentials Management
|
CVE-2015-7258
|
2024-11-21 11:36 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267780
|
7.5 |
HIGH
Network
|
zte
|
zxv10_w300_firmware
|
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password chang…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2015-7257
|
2024-11-21 11:36 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|