|
267181
|
7.5 |
HIGH
Network
|
openpgpjs
|
openpgpjs
|
s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentic…
|
CWE-310
Cryptographic Issues
|
CVE-2015-8013
|
2024-11-21 11:37 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267182
|
9.8 |
CRITICAL
Network
|
mediawiki
|
mediawiki
|
The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4, and before 1.23.11 does not properly validate the signature when checking the …
|
CWE-255
Credentials Management
|
CVE-2015-8009
|
2024-11-21 11:37 |
2017-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267183
|
7.5 |
HIGH
Network
|
ntp oracle debian netapp redhat
|
ntp linux debian_linux clustered_data_ontap data_ontap oncommand_unified_manager oncommand_performance_manager enterprise_linux_desktop enterprise_linux_workstation enterpr…
|
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address th…
|
CWE-20
Improper Input Validation
|
CVE-2015-7703
|
2024-11-21 11:37 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267184
|
5.5 |
MEDIUM
Local
|
samsung
|
samsung_mobile
|
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
|
CWE-284
Improper Access Control
|
CVE-2015-7898
|
2024-11-21 11:37 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267185
|
5.5 |
MEDIUM
Local
|
samsung
|
samsung_mobile
|
Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
|
CWE-284
Improper Access Control
|
CVE-2015-7895
|
2024-11-21 11:37 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267186
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_firewall_analyzer
|
ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.
|
CWE-275
Permission Issues
|
CVE-2015-7781
|
2024-11-21 11:37 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267187
|
6.5 |
MEDIUM
Network
|
zohocorp
|
manageengine_firewall_analyzer
|
Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
|
CWE-22
Path Traversal
|
CVE-2015-7780
|
2024-11-21 11:37 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267188
|
7.5 |
HIGH
Network
|
avira
|
avira_mobile_security
|
The Avira Mobile Security app before 1.5.11 for iOS sends sensitive login information in cleartext.
|
CWE-200
Information Exposure
|
CVE-2015-7732
|
2024-11-21 11:37 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267189
|
7.5 |
HIGH
Network
|
samsung
|
galaxy_s6_edge_firmware
|
Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via…
|
CWE-22
Path Traversal
|
CVE-2015-7888
|
2024-11-21 11:37 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267190
|
7.8 |
HIGH
Local
|
amd
|
fglrx-driver
|
AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723.
|
CWE-59
Link Following
|
CVE-2015-7724
|
2024-11-21 11:37 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|