|
269681
|
7.3 |
HIGH
Network
|
php
|
php
|
Use-after-free vulnerability in the SPL unserialize implementation in ext/spl/spl_array.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to execute arbitra…
|
NVD-CWE-Other
|
CVE-2015-6832
|
2024-11-21 11:35 |
2016-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269682
|
7.3 |
HIGH
Network
|
php debian
|
php debian_linux
|
Multiple use-after-free vulnerabilities in SPL in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allow remote attackers to execute arbitrary code via vectors involving (1) ArrayObjec…
|
CWE-416
Use After Free
|
CVE-2015-6831
|
2024-11-21 11:35 |
2016-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269683
|
7.3 |
HIGH
Network
|
php
|
php
|
The php_str_replace_in_subject function in ext/standard/string.c in PHP 7.x before 7.0.0 allows remote attackers to execute arbitrary code via a crafted value in the third argument to the str_ireplac…
|
NVD-CWE-noinfo
|
CVE-2015-6527
|
2024-11-21 11:35 |
2016-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269684
|
6.3 |
MEDIUM
Network
|
hp
|
arcsight_logger
|
HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
|
CWE-20
Improper Input Validation
|
CVE-2015-6864
|
2024-11-21 11:35 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269685
|
7.3 |
HIGH
Network
|
hp
|
arcsight_logger
|
HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.
|
CWE-20
Improper Input Validation
|
CVE-2015-6863
|
2024-11-21 11:35 |
2016-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269686
|
8.1 |
HIGH
Network
|
advantech
|
webaccess
|
Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin.
|
NVD-CWE-noinfo
|
CVE-2015-6467
|
2024-11-21 11:35 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269687
|
8.4 |
HIGH
Local
|
zarafa fedoraproject
|
zarafa_collaboration_platform fedora
|
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.
|
CWE-59
Link Following
|
CVE-2015-6566
|
2024-11-21 11:35 |
2016-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269688
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
Directory Utility in Apple OS X before 10.11.1 mishandles authentication for new sessions, which allows local users to gain privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-6980
|
2024-11-21 11:35 |
2016-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269689
|
6.3 |
MEDIUM
Network
|
vmware
|
player workstation esxi fusion
|
The VMware Tools HGFS (aka Shared Folders) implementation in VMware Workstation 11.x before 11.1.2, VMware Player 7.x before 7.1.2, VMware Fusion 7.x before 7.1.2, and VMware ESXi 5.0 through 6.0 all…
|
CWE-284
Improper Access Control
|
CVE-2015-6933
|
2024-11-21 11:35 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269690
|
7.8 |
HIGH
Local
|
dell
|
pre-boot_authentication_driver
|
Dell Pre-Boot Authentication Driver (PBADRV.sys) 1.0.1.5 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x0022201c IOCTL call.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-6856
|
2024-11-21 11:35 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|