|
269641
|
7.8 |
HIGH
Local
|
lenovo
|
system_update
|
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed …
|
CWE-77
Command Injection
|
CVE-2015-6971
|
2024-11-21 11:35 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269642
|
8.8 |
HIGH
Network
|
atlassian
|
bamboo
|
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
|
CWE-94
Code Injection
|
CVE-2015-6576
|
2024-11-21 11:35 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269643
|
6.8 |
MEDIUM
Physics
|
huawei
|
uap2105_firmware
|
Huawei UAP2105 before V300R012C00SPC160(BootRom) does not require authentication to the serial port or the VxWorks shell.
|
CWE-254
7PK - Security Features
|
CVE-2015-6592
|
2024-11-21 11:35 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269644
|
6.1 |
MEDIUM
Network
|
jsoup debian
|
jsoup debian_linux
|
Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6748
|
2024-11-21 11:35 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269645
|
9.8 |
CRITICAL
Network
|
libpgf
|
libpgf
|
Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32.
|
CWE-416
Use After Free
|
CVE-2015-6673
|
2024-11-21 11:35 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269646
|
6.1 |
MEDIUM
Network
|
coremail
|
coremail_xt
|
Cross-site scripting (XSS) vulnerability in Coremail XT3.0 allows remote attackers to inject arbitrary web script or HTML via a hyperlink in a document attachment.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6942
|
2024-11-21 11:35 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269647
|
6.1 |
MEDIUM
Network
|
modx
|
modx_revolution
|
Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6588
|
2024-11-21 11:35 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269648
|
9.8 |
CRITICAL
Network
|
wago
|
750-849_firmware 758-870_firmware
|
WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.
|
CWE-254
7PK - Security Features
|
CVE-2015-6473
|
2024-11-21 11:35 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269649
|
9.8 |
CRITICAL
Network
|
wago
|
750-849_firmware 750-881_firmware 758-870_firmware
|
WAGO IO 750-849 01.01.27 and 01.02.05, WAGO IO 750-881, and WAGO IO 758-870 have weak credential management.
|
CWE-255
Credentials Management
|
CVE-2015-6472
|
2024-11-21 11:35 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269650
|
9.8 |
CRITICAL
Network
|
fedoraproject ganglia
|
fedora ganglia-web
|
ganglia-web before 3.7.1 allows remote attackers to bypass authentication.
|
CWE-287
Improper Authentication
|
CVE-2015-6816
|
2024-11-21 11:35 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|