|
269201
|
7.8 |
HIGH
Local
|
ciphershed idrix truecrypt
|
ciphershed veracrypt truecrypt
|
The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation leve…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7359
|
2024-11-21 11:36 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269202
|
7.8 |
HIGH
Local
|
ciphershed idrix truecrypt
|
ciphershed veracrypt truecrypt
|
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7358
|
2024-11-21 11:36 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269203
|
6.1 |
MEDIUM
Network
|
udesign_project
|
udesign
|
Cross-site scripting (XSS) vulnerability in the uDesign (aka U-Design) theme 2.3.0 before 2.7.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via a fragment identifier…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7357
|
2024-11-21 11:36 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269204
|
6.1 |
MEDIUM
Network
|
vasco
|
digipass
|
Cross-site scripting (XSS) vulnerability in the sample feedback.inc file in VASCO DIGIPASS authentication plug-in for Citrix Web Interface allows remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7349
|
2024-11-21 11:36 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269205
|
5.9 |
MEDIUM
Network
|
zyxel
|
nwa1100-n_firmware nwa1100-nh_firmware nwa1121-ni_firmware nwa1123-ac_firmware nwa1123-ni_firmware p-660hn-51_firmware p-663hn-51_firmware vmg1312-b10a_firmware vmg1312-b30a_f…
|
ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-…
|
CWE-310
Cryptographic Issues
|
CVE-2015-7256
|
2024-11-21 11:36 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269206
|
6.1 |
MEDIUM
Network
|
testlink
|
testlink
|
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML via the (1) selected_end_date or (2) selected_start_date pa…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7391
|
2024-11-21 11:36 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269207
|
9.8 |
CRITICAL
Network
|
testlink
|
testlink
|
SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.
|
CWE-89
SQL Injection
|
CVE-2015-7390
|
2024-11-21 11:36 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269208
|
9.1 |
CRITICAL
Network
|
redhat
|
enterprise_virtualization_manager
|
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary comm…
|
CWE-74
Injection
|
CVE-2015-7544
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269209
|
9.8 |
CRITICAL
Network
|
systemd_project
|
systemd
|
Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7510
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269210
|
8.8 |
HIGH
Network
|
plone zope
|
plone zope_management_interface
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
|
CWE-352
Origin Validation Error
|
CVE-2015-7293
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|