|
266971
|
- |
|
bitrix
|
mpbuilder
|
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the element n…
|
CWE-22
Path Traversal
|
CVE-2015-8358
|
2024-11-21 11:38 |
2015-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266972
|
- |
|
bitrix
|
xscan
|
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and consequently obtain sensitive information or caus…
|
CWE-22
Path Traversal
|
CVE-2015-8357
|
2024-11-21 11:38 |
2015-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266973
|
- |
|
kaspersky
|
total_security_2015
|
Kaspersky Total Security 2015 15.0.2.361 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses when protecting user-mode processes, which allows attackers to bypass th…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8579
|
2024-11-21 11:38 |
2015-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266974
|
- |
|
avg
|
internet_security
|
AVG Internet Security 2015 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses when protecting user-mode processes, which allows attackers to bypass the DEP and ASLR…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8578
|
2024-11-21 11:38 |
2015-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266975
|
- |
|
mcafee
|
virusscan_enterprise
|
The Buffer Overflow Protection (BOP) feature in McAfee VirusScan Enterprise before 8.8 Patch 6 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses on 32-bit platform…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8577
|
2024-11-21 11:38 |
2015-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266976
|
- |
|
isc
|
bind
|
Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via…
|
CWE-362
Race Condition
|
CVE-2015-8461
|
2024-11-21 11:38 |
2015-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266977
|
- |
|
autodesk
|
design_review
|
Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lin…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8572
|
2024-11-21 11:38 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266978
|
- |
|
autodesk
|
design_review
|
Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code via a crafted biClrUsed value in a BMP file, which triggers a buffer overflow.
|
CWE-189
Numeric Errors
|
CVE-2015-8571
|
2024-11-21 11:38 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266979
|
- |
|
lepide
|
active_directory_self_service
|
The password reset functionality in Lepide Active Directory Self Service allows remote authenticated users to change arbitrary domain user passwords via a crafted request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8570
|
2024-11-21 11:38 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266980
|
- |
|
cacti
|
cacti
|
SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serializ…
|
CWE-89
SQL Injection
|
CVE-2015-8377
|
2024-11-21 11:38 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|