|
267271
|
4.3 |
MEDIUM
Adjacent
|
asus
|
wl-33nul_firmware wl-330nul
|
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to cause a denial of service via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2015-7789
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267272
|
7.3 |
HIGH
Network
|
asus
|
wl-330nul_firmware
|
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to execute arbitrary commands via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7788
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267273
|
4.3 |
MEDIUM
Adjacent
|
asus
|
wl-330nul_firmware
|
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to discover the WPA2-PSK passphrase via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-7787
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267274
|
4.3 |
MEDIUM
Network
|
bokublock
|
bbadminviewscontrol213 bbadminviewscontrol
|
SQL injection vulnerability in the BOKUBLOCK (1) BbAdminViewsControl213 plugin before 1.1 and (2) BbAdminViewsControl plugin before 2.1 for EC-CUBE allows remote authenticated users to execute arbitr…
|
CWE-89
SQL Injection
|
CVE-2015-7784
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267275
|
6.1 |
MEDIUM
Network
|
let\'s_php\!
|
frame_high-speed_chat
|
Cross-site scripting (XSS) vulnerability in Let's PHP! Frame high-speed chat before 2015-09-22 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7782
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267276
|
6.3 |
MEDIUM
Network
|
collne
|
welcart
|
Multiple SQL injection vulnerabilities in admin.php in the Collne Welcart plugin before 1.5.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) search[colum…
|
CWE-89
SQL Injection
|
CVE-2015-7791
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267277
|
6.1 |
MEDIUM
Network
|
nttdata
|
web_analytics_service
|
Cross-site scripting (XSS) vulnerability in the NTT DATA Smart Sourcing JavaScript module 2003-11-26 through 2013-07-09 for Web Analytics Service allows remote attackers to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7786
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267278
|
5.8 |
MEDIUM
Local
|
linux
|
linux_kernel
|
Race condition in the rds_sendmsg function in net/rds/sendmsg.c in the Linux kernel before 4.3.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibl…
|
CWE-362
Race Condition
|
CVE-2015-7990
|
2024-11-21 11:37 |
2015-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267279
|
2.3 |
LOW
Local
|
linux
|
linux_kernel
|
The dgnc_mgmt_ioctl function in drivers/staging/dgnc/dgnc_mgmt.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive informa…
|
CWE-200
Information Exposure
|
CVE-2015-7885
|
2024-11-21 11:37 |
2015-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267280
|
2.3 |
LOW
Local
|
linux
|
linux_kernel
|
The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive …
|
CWE-200
Information Exposure
|
CVE-2015-7884
|
2024-11-21 11:37 |
2015-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|