|
266421
|
- |
|
canonical oracle
|
ubuntu_linux jdk jre
|
Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect integrity via unknown vect…
|
NVD-CWE-noinfo
|
CVE-2016-0402
|
2024-11-21 11:41 |
2016-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266422
|
- |
|
oracle
|
fusion_middleware
|
Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0 and 11.1.1.9.0 allows remote attackers to affect integrity via unknown vectors related to Schedul…
|
NVD-CWE-noinfo
|
CVE-2016-0401
|
2024-11-21 11:41 |
2016-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266423
|
5.9 |
MEDIUM
Network
|
ibm
|
security_network_protection_firmware
|
GSKit in IBM Security Network Protection 5.3.1 before 5.3.1.7 and 5.3.2 allows remote attackers to discover credentials by triggering an MD5 collision.
|
CWE-200
Information Exposure
|
CVE-2016-0201
|
2024-11-21 11:41 |
2016-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266424
|
9.8 |
CRITICAL
Network
|
totolink
|
a850r-v1_firmware f1-v2_firmware f2-v1_firmware n150rt-v2_firmware n151rt-v2_firmware n300rh-v2_firmware n300rh-v3_firmware n300rt-v2_firmware
|
An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution in the management interface via the formSysCmd s…
|
NVD-CWE-noinfo
|
CVE-2015-9551
|
2024-11-21 11:40 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266425
|
7.5 |
HIGH
Network
|
totolink
|
a850r-v1_firmware f1-v2_firmware f2-v1_firmware n150rt-v2_firmware n151rt-v2_firmware n300rh-v2_firmware n300rh-v3_firmware n300rt-v2_firmware
|
An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. By sending a specific hel,xasf packet to the WAN interface, it is possible to o…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2015-9550
|
2024-11-21 11:40 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266426
|
6.1 |
MEDIUM
Network
|
ocportal
|
ocportal
|
A reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME field to data/emoticons.php.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9549
|
2024-11-21 11:40 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266427
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compressed file that has a large size when uncompressed.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-9548
|
2024-11-21 11:40 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266428
|
7.5 |
HIGH
Network
|
google
|
android
|
An issue was discovered on Samsung mobile devices with JBP(4.3) and KK(4.4.2) software. Because the READ_LOGS permission is mishandled, sensitive information is disclosed in a world-readable copy of …
|
CWE-200
Information Exposure
|
CVE-2015-9547
|
2024-11-21 11:40 |
2020-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266429
|
4.8 |
MEDIUM
Network
|
google
|
android
|
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker c…
|
CWE-22
Path Traversal
|
CVE-2015-9546
|
2024-11-21 11:40 |
2020-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266430
|
7.1 |
HIGH
Local
|
cross_domain_local_storage_project
|
cross_domain_local_storage
|
An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not implement any validation of the origin of web messages. Remote attackers who can e…
|
CWE-20
Improper Input Validation
|
CVE-2015-9545
|
2024-11-21 11:40 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|