|
267251
|
9.8 |
CRITICAL
Network
|
sauter
|
moduweb_vision
|
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
|
CWE-255 CWE-200
Credentials Management Information Exposure
|
CVE-2015-7915
|
2024-11-21 11:37 |
2016-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267252
|
8.1 |
HIGH
Network
|
sauter
|
moduweb_vision
|
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge of a password hash without knowledge of the associated password.
|
CWE-287 CWE-254
Improper Authentication 7PK - Security Features
|
CVE-2015-7914
|
2024-11-21 11:37 |
2016-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267253
|
9.0 |
CRITICAL
Network
|
westermo
|
weos
|
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanism…
|
CWE-310
Cryptographic Issues
|
CVE-2015-7923
|
2024-11-21 11:37 |
2016-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267254
|
7.7 |
HIGH
Network
|
ntp siemens netapp debian
|
ntp tim_4r-ie_firmware tim_4r-ie_dnp3_firmware oncommand_balance clustered_data_ontap debian_linux
|
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via a…
|
CWE-287
Improper Authentication
|
CVE-2015-7974
|
2024-11-21 11:37 |
2016-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267255
|
5.9 |
MEDIUM
Network
|
wolfssl opensuse mariadb
|
wolfssl leap opensuse mariadb
|
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimization…
|
NVD-CWE-noinfo
|
CVE-2015-7744
|
2024-11-21 11:37 |
2016-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267256
|
7.3 |
HIGH
Network
|
hospira
|
communication_engine lifecare_pca_infusion_system
|
Stack-based buffer overflow in Hospira Communication Engine (CE) before 1.2 in LifeCare PCA Infusion System 5.07, Plum A+ Infusion System 13.40, and Plum A+3 Infusion System 13.40 allows remote attac…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7909
|
2024-11-21 11:37 |
2016-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267257
|
3.7 |
LOW
Network
|
netapp
|
data_ontap
|
NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive volume information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-7886
|
2024-11-21 11:37 |
2016-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267258
|
3.7 |
LOW
Network
|
f5
|
big-ip_analytics big-ip_application_acceleration_manager big-ip_link_controller big-ip_advanced_firewall_manager big-ip_policy_enforcement_manager big-ip_local_traffic_manager big-i…
|
BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 12.0.0 before HF1, when the TCP profile for a virtual server is configured with Congestion Metrics Cache enabled, allow remote atta…
|
CWE-20
Improper Input Validation
|
CVE-2015-7759
|
2024-11-21 11:37 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267259
|
7.8 |
HIGH
Local
|
huawei
|
p8_firmware mate_7_firmware
|
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7-TL10 before MT7-TL10C00B354, MT7-TL00 before MT7-TL00C01B354, and MT7-CL00 bef…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8088
|
2024-11-21 11:37 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267260
|
6.1 |
MEDIUM
Network
|
ssp-europe
|
secure_data_space
|
Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to api/v3/public/shar…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7706
|
2024-11-21 11:37 |
2016-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|