|
268531
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, a NULL pointer may be dereferenced in the front end.
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-9038
|
2024-11-21 11:39 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268532
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read may occur in the processing of a downlink 3G NAS message.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-9037
|
2024-11-21 11:39 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268533
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, an incorrect length is used to clear a memory buffer resulting in adjacent memory getting corrupted.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-9036
|
2024-11-21 11:39 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268534
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, a memory buffer fails to be freed after it is no longer needed potentially resulting in memory exhaustion.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-9035
|
2024-11-21 11:39 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268535
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, a string can fail to be null-terminated in SIP leading to a buffer overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-9034
|
2024-11-21 11:39 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268536
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_opmanager
|
Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key o…
|
CWE-310
Cryptographic Issues
|
CVE-2015-9107
|
2024-11-21 11:39 |
2017-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268537
|
5.4 |
MEDIUM
Network
|
synology
|
video_station
|
Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrar…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9105
|
2024-11-21 11:39 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268538
|
5.4 |
MEDIUM
Network
|
synology
|
audio_station
|
Cross-site scripting (XSS) vulnerabilities in Synology Audio Station 5.1 before 5.1-2550 and 5.4 before 5.4-2857 allows remote authenticated attackers to inject arbitrary web script or HTML via the a…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9104
|
2024-11-21 11:39 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268539
|
5.4 |
MEDIUM
Network
|
synology
|
note_station
|
Multiple cross-site scripting (XSS) vulnerabilities in Synology Note Station 1.1-0212 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) note title or…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9103
|
2024-11-21 11:39 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268540
|
5.4 |
MEDIUM
Network
|
synology
|
photo_station
|
Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote authenticated attackers to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9102
|
2024-11-21 11:39 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|