|
267791
|
8.8 |
HIGH
Network
|
teampass
|
teampass
|
Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user.
|
CWE-352
Origin Validation Error
|
CVE-2015-7563
|
2024-11-21 11:36 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267792
|
6.1 |
MEDIUM
Network
|
teampass
|
teampass
|
Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) label value of an item or (2) name of a ro…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7562
|
2024-11-21 11:36 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267793
|
9.8 |
CRITICAL
Network
|
amazon
|
fire_os
|
Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attackers to cause a denial of service (panic) or possibly have uns…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7292
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267794
|
6.1 |
MEDIUM
Network
|
dell
|
integrated_remote_access_controller_firmware
|
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7275
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267795
|
8.8 |
HIGH
Network
|
dell
|
integrated_remote_access_controller_firmware
|
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrative HTTP commands.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7274
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267796
|
9.8 |
CRITICAL
Network
|
dell
|
integrated_remote_access_controller_firmware
|
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.
|
CWE-611
XXE
|
CVE-2015-7273
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267797
|
9.8 |
CRITICAL
Network
|
dell
|
integrated_remote_access_controller_firmware
|
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7272
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267798
|
9.8 |
CRITICAL
Network
|
dell
|
integrated_remote_access_controller_firmware
|
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2015-7271
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267799
|
7.8 |
HIGH
Local
|
dell
|
integrated_remote_access_controller_firmware
|
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.
|
CWE-22
Path Traversal
|
CVE-2015-7270
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267800
|
7.5 |
HIGH
Network
|
proxygen_project
|
proxygen
|
Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.
|
CWE-284
Improper Access Control
|
CVE-2015-7265
|
2024-11-21 11:36 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|