|
267711
|
7.2 |
HIGH
Network
|
gwesystems
|
jevents
|
JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action.
|
CWE-89
SQL Injection
|
CVE-2015-7340
|
2024-11-21 11:36 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267712
|
8.8 |
HIGH
Network
|
widgetfactorylimited
|
jce
|
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-7339
|
2024-11-21 11:36 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267713
|
7.2 |
HIGH
Network
|
acyba
|
acymailing
|
SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.
|
CWE-89
SQL Injection
|
CVE-2015-7338
|
2024-11-21 11:36 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267714
|
4.8 |
MEDIUM
Network
|
hikashop
|
hikashop
|
HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption].
|
CWE-79
Cross-site Scripting
|
CVE-2015-7344
|
2024-11-21 11:36 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267715
|
4.8 |
MEDIUM
Network
|
joobi
|
jnews
|
JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7343
|
2024-11-21 11:36 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267716
|
7.5 |
HIGH
Network
|
netsurf-browser
|
libnsbmp
|
libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_decode_rle function.
|
CWE-125
Out-of-bounds Read
|
CVE-2015-7507
|
2024-11-21 11:36 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267717
|
9.8 |
CRITICAL
Network
|
yeager
|
yeager_cms
|
SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token" parameter.
|
CWE-89
SQL Injection
|
CVE-2015-7567
|
2024-11-21 11:36 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267718
|
8.8 |
HIGH
Network
|
netsurf-browser
|
libnsgif
|
Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitr…
|
CWE-787
Out-of-bounds Write
|
CVE-2015-7505
|
2024-11-21 11:36 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267719
|
6.5 |
MEDIUM
Network
|
netsurf-browser
|
libnsgif
|
The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF …
|
CWE-125
Out-of-bounds Read
|
CVE-2015-7506
|
2024-11-21 11:36 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267720
|
8.8 |
HIGH
Network
|
netsurf-browser
|
libnsbmp
|
Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbit…
|
CWE-787
Out-of-bounds Write
|
CVE-2015-7508
|
2024-11-21 11:36 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|