|
271011
|
9.8 |
CRITICAL
Network
|
trane
|
comfortlink_ii_firmware
|
An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can connect to the DSS service on the Trane ComfortLink II…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2868
|
2024-11-21 11:28 |
2017-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271012
|
9.8 |
CRITICAL
Network
|
trane
|
comfortlink_ii_firmware
|
A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2015-2867
|
2024-11-21 11:28 |
2017-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271013
|
7.5 |
HIGH
Network
|
pcre ibm
|
pcre2 pcre powerkvm
|
PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expr…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3217
|
2024-11-21 11:28 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271014
|
9.8 |
CRITICAL
Network
|
pcre
|
pcre2 pcre
|
Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)…
|
CWE-787
Out-of-bounds Write
|
CVE-2015-3210
|
2024-11-21 11:28 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271015
|
5.5 |
MEDIUM
Local
|
pivotal_software vmware fedoraproject
|
spring_framework fedora
|
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of servi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3192
|
2024-11-21 11:28 |
2016-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271016
|
5.9 |
MEDIUM
Network
|
oracle mariadb fedoraproject debian redhat php
|
mysql mysql_connector\/c mariadb fedora debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_eus enterprise_linux_ser…
|
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle atta…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-3152
|
2024-11-21 11:28 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271017
|
7.5 |
HIGH
Network
|
libssh canonical debian fedoraproject
|
libssh ubuntu_linux debian_linux fedora
|
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (…
|
NVD-CWE-Other
|
CVE-2015-3146
|
2024-11-21 11:28 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271018
|
5.9 |
MEDIUM
Network
|
erlang oracle opensuse
|
erlang\/otp solaris opensuse
|
Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle …
|
CWE-200
Information Exposure
|
CVE-2015-2774
|
2024-11-21 11:28 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271019
|
5.9 |
MEDIUM
Network
|
oracle openssl
|
tuxedo exalogic_infrastructure peoplesoft_enterprise_peopletools openssl oss_support_tools vm_virtualbox
|
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection…
|
CWE-310 CWE-200
Cryptographic Issues Information Exposure
|
CVE-2015-3197
|
2024-11-21 11:28 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271020
|
9.8 |
CRITICAL
Network
|
apache
|
cloudstack
|
Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.
|
CWE-255
Credentials Management
|
CVE-2015-3252
|
2024-11-21 11:28 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|