|
269651
|
7.5 |
HIGH
Network
|
alcatel-lucent
|
home_device_manager
|
Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as target devices.
|
CWE-254
7PK - Security Features
|
CVE-2015-6498
|
2024-11-21 11:35 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269652
|
9.8 |
CRITICAL
Network
|
saltstack
|
salt_2015
|
win_useradd, salt-cloud and the Linode driver in salt 2015.5.x before 2015.5.6, and 2015.8.x before 2015.8.1 leak password information in debug logs.
|
CWE-534
DEPRECATED: Information Exposure Through Debug Log Files
|
CVE-2015-6941
|
2024-11-21 11:35 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269653
|
7.8 |
HIGH
Local
|
hancom
|
hangul_word_processor
|
hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type confusion" via an HWPX file containing a crafted para text ta…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6585
|
2024-11-21 11:35 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269654
|
5.4 |
MEDIUM
Network
|
vindula
|
vindula
|
Cross-site scripting (XSS) vulnerability in Vindula 1.9.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6959
|
2024-11-21 11:35 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269655
|
6.1 |
MEDIUM
Network
|
igcb
|
intellect_digital_core
|
Cross-site scripting (XSS) vulnerability in Intellect Design Arena Intellect Core banking software.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6540
|
2024-11-21 11:35 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269656
|
7.8 |
HIGH
Local
|
paloaltonetworks
|
pan-os
|
Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.
|
CWE-94
Code Injection
|
CVE-2015-6531
|
2024-11-21 11:35 |
2017-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269657
|
8.1 |
HIGH
Network
|
pgbouncer
|
pgbouncer
|
PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.
|
CWE-287
Improper Authentication
|
CVE-2015-6817
|
2024-11-21 11:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269658
|
7.5 |
HIGH
Network
|
huawei
|
wlan_acu2_firmware wlan_ac6005_firmware wlan_ac6605_firmware
|
The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote attackers to obtain sensitive information by leveraging failure to restrict proces…
|
CWE-200
Information Exposure
|
CVE-2015-6586
|
2024-11-21 11:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269659
|
8.8 |
HIGH
Network
|
wolfcms
|
wolf_cms
|
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" …
|
CWE-20
Improper Input Validation
|
CVE-2015-6568
|
2024-11-21 11:35 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269660
|
8.8 |
HIGH
Network
|
wolfcms
|
wolf_cms
|
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exp…
|
CWE-20
Improper Input Validation
|
CVE-2015-6567
|
2024-11-21 11:35 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|