|
273341
|
- |
|
oracle mozilla
|
solaris firefox
|
The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-0798
|
2024-11-21 11:23 |
2015-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273342
|
- |
|
bblog_project
|
bblog
|
Cross-site request forgery (CSRF) vulnerability in bBlog allows remote attackers to hijack the authentication of arbitrary users.
|
CWE-352
Origin Validation Error
|
CVE-2015-0905
|
2024-11-21 11:23 |
2015-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273343
|
- |
|
saurus
|
saurus_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in the print_language_selectbox function in classes/adminpage.inc.php in Saurus CMS Community Edition before 4.7 2015-02-04 allow remote attackers …
|
CWE-79
Cross-site Scripting
|
CVE-2015-0876
|
2024-11-21 11:23 |
2015-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273344
|
- |
|
cisco
|
wireless_lan_controller_software
|
Cross-site scripting (XSS) vulnerability in the HTML help system on Cisco Wireless LAN Controller (WLC) devices before 8.0 allows remote attackers to inject arbitrary web script or HTML via a crafted…
|
CWE-79
Cross-site Scripting
|
CVE-2015-0690
|
2024-11-21 11:23 |
2015-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273345
|
- |
|
c-board_moyuku_project
|
c-board_moyuku
|
Unrestricted file upload vulnerability in app/lib/mlf.pl in C-BOARD Moyuku before 1.03b3 allows remote attackers to execute arbitrary code by uploading a file with a \0 character in its name.
|
NVD-CWE-Other
|
CVE-2015-0877
|
2024-11-21 11:23 |
2015-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273346
|
- |
|
xen
|
xen
|
drivers/xen/usbback/usbback.c in linux-2.6.18-xen-3.4.0 (aka the Xen 3.4.x support patches for the Linux kernel 2.6.18), as used in the Linux kernel 2.6.x and 3.x in SUSE Linux distributions, allows …
|
CWE-200
Information Exposure
|
CVE-2015-0777
|
2024-11-21 11:23 |
2015-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273347
|
- |
|
emc
|
powerpath_virtual_appliance
|
EMC PowerPath Virtual Appliance (aka vApp) before 2.0 has default passwords for the (1) emcupdate and (2) svcuser accounts, which makes it easier for remote attackers to obtain potentially sensitive …
|
CWE-255
Credentials Management
|
CVE-2015-0529
|
2024-11-21 11:23 |
2015-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273348
|
- |
|
cisco
|
ios_xe
|
Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.3…
|
CWE-399
Resource Management Errors
|
CVE-2015-0688
|
2024-11-21 11:23 |
2015-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273349
|
- |
|
cisco
|
unity_connection
|
The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, and 9.x before 9.1(2)SU2, when SIP trunk integration is enabled, allow…
|
CWE-19
Data Processing Errors
|
CVE-2015-0616
|
2024-11-21 11:23 |
2015-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273350
|
- |
|
cisco
|
unity_connection
|
The call-handling implementation in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows…
|
CWE-19
Data Processing Errors
|
CVE-2015-0615
|
2024-11-21 11:23 |
2015-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|