|
267441
|
7.5 |
HIGH
Network
|
wpmobilepack
|
wordpress_mobile_pack
|
The export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 2015-06-03 for WordPress allows remote attackers to obtain sensitive information because the content of a…
|
CWE-200
Information Exposure
|
CVE-2015-9269
|
2024-11-21 11:40 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267442
|
7.8 |
HIGH
Local
|
nullsoft debian
|
nullsoft_scriptable_install_system debian_linux
|
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the depend…
|
CWE-20
Improper Input Validation
|
CVE-2015-9268
|
2024-11-21 11:40 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267443
|
5.5 |
MEDIUM
Local
|
nullsoft debian
|
nullsoft_scriptable_install_system debian_linux
|
Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or th…
|
CWE-269
Improper Privilege Management
|
CVE-2015-9267
|
2024-11-21 11:40 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267444
|
9.8 |
CRITICAL
Network
|
ui ubnt
|
airmax_ac_firmware airmax_m_xm_firmware airmax_m_xw_firmware airmax_m_ti_firmware airgateway_firmware airfiber_af24_firmware airfiber_af24hd_firmware af5x_firmware af5_firmwar…
|
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory t…
|
CWE-22
Path Traversal
|
CVE-2015-9266
|
2024-11-21 11:40 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267445
|
9.8 |
CRITICAL
Network
|
lansweeper
|
lansweeper
|
Lansweeper 4.x through 6.x before 6.0.0.48 allows attackers to execute arbitrary code on the administrator's workstation via a crafted Windows service.
|
CWE-20
Improper Input Validation
|
CVE-2015-9264
|
2024-11-21 11:40 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267446
|
9.8 |
CRITICAL
Network
|
idera
|
uptime_infrastructure_monitor
|
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute a…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-9263
|
2024-11-21 11:40 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267447
|
9.8 |
CRITICAL
Network
|
debian canonical x redhat
|
debian_linux ubuntu_linux libxcursor enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ansible_tower
|
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-9262
|
2024-11-21 11:40 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267448
|
5.5 |
MEDIUM
Local
|
busybox debian canonical
|
busybox debian_linux ubuntu_linux
|
huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-9261
|
2024-11-21 11:40 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267449
|
5.4 |
MEDIUM
Network
|
bedita
|
bedita
|
An issue was discovered in BEdita before 3.7.0. A cross-site scripting (XSS) attack occurs via a crafted pages/showObjects URI, as demonstrated by appending a payload to a pages/showObjects/2/0/0/lea…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9260
|
2024-11-21 11:40 |
2018-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267450
|
7.5 |
HIGH
Network
|
ansi2html_project
|
ansi2html
|
ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in.
|
CWE-20
Improper Input Validation
|
CVE-2015-9239
|
2024-11-21 11:40 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|