|
268781
|
- |
|
refbase
|
refbase
|
install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword parameter, a different issue than CVE-2015-7381.
|
CWE-78
OS Command
|
CVE-2015-6008
|
2024-11-21 11:34 |
2015-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268782
|
- |
|
refbase
|
refbase
|
Cross-site request forgery (CSRF) vulnerability in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to hijack the authentication of arbitrary users.
|
CWE-352
Origin Validation Error
|
CVE-2015-6007
|
2024-11-21 11:34 |
2015-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268783
|
- |
|
everest
|
peakhmi
|
Everest PeakHMI before 8.7.0.2, when the video server is used, allows remote attackers to cause a denial of service (incorrect pointer dereference and daemon crash) via a crafted packet.
|
NVD-CWE-Other
|
CVE-2015-6454
|
2024-11-21 11:34 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268784
|
- |
|
cisco
|
anyconnect_secure_mobility_client
|
Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation f…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-6306
|
2024-11-21 11:34 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268785
|
- |
|
cisco
|
anyconnect_secure_mobility_client
|
Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConnect Secure Mobility Client 2.0 through 4.1 on Windows allows local users to gain…
|
CWE-426
Untrusted Search Path
|
CVE-2015-6305
|
2024-11-21 11:34 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268786
|
- |
|
cisco
|
wireless_lan_controller_software
|
The RADIUS functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.0(250.0) and 7.0(252.0) allows remote attackers to disconnect arbitrary sessions via crafted Disconnect-Request…
|
CWE-399
Resource Management Errors
|
CVE-2015-6302
|
2024-11-21 11:34 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268787
|
- |
|
cisco
|
ios_xe
|
Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15.1S allows remote attackers to cause a denial of service (device reload) via IP…
|
CWE-20 CWE-399
Improper Input Validation Resource Management Errors
|
CVE-2015-6282
|
2024-11-21 11:34 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268788
|
- |
|
cisco
|
telepresence_server_software
|
Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Server software 3.0(2.24) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCut63718, CSCut6…
|
CWE-352
Origin Validation Error
|
CVE-2015-6304
|
2024-11-21 11:34 |
2015-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268789
|
- |
|
cisco
|
spark
|
The Cisco Spark application 2015-07-04 for mobile operating systems does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain …
|
CWE-200
Information Exposure
|
CVE-2015-6303
|
2024-11-21 11:34 |
2015-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268790
|
- |
|
sumome
|
google_analyticator
|
Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6238
|
2024-11-21 11:34 |
2015-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|