|
269881
|
- |
|
gnu
|
gnu_screen
|
The MScrollV function in ansi.c in GNU screen 4.3.1 and earlier does not properly limit recursion, which allows remote attackers to cause a denial of service (stack consumption) via an escape sequenc…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6806
|
2024-11-21 11:35 |
2015-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269882
|
- |
|
cubecart
|
cubecart
|
classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administr…
|
CWE-284
Improper Access Control
|
CVE-2015-6928
|
2024-11-21 11:35 |
2015-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269883
|
- |
|
codewrights endress\+hauser
|
hart_comm_dtm
|
CodeWrights HART Comm DTM components, as used with Endress+Hauser FieldCare, allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU …
|
NVD-CWE-Other
|
CVE-2015-6463
|
2024-11-21 11:35 |
2015-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269884
|
- |
|
ibc_solar
|
danfoss_tlx_pro\+ servemaster_tlp\+
|
Multiple cross-site scripting (XSS) vulnerabilities in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6475
|
2024-11-21 11:35 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269885
|
- |
|
ibc_solar
|
danfoss_tlx_pro\+ servemaster_tlp\+
|
IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to discover cleartext passwords by reading HTML source code.
|
CWE-200
Information Exposure
|
CVE-2015-6474
|
2024-11-21 11:35 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269886
|
- |
|
resource_data_management_data_manager
|
data_manager
|
Resource Data Management Data Manager before 2.2 allows remote authenticated users to modify arbitrary passwords via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2015-6470
|
2024-11-21 11:35 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269887
|
- |
|
ibc_solar
|
danfoss_tlx_pro\+ servemaster_tlp\+
|
The interpreter in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allows remote attackers to discover script source code via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-6469
|
2024-11-21 11:35 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269888
|
- |
|
resource_data_management_data_manager
|
data_manager
|
Cross-site request forgery (CSRF) vulnerability in Resource Data Management Data Manager before 2.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2015-6468
|
2024-11-21 11:35 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269889
|
- |
|
pentaho
|
data_integration business_analytics
|
The GetResource servlet in Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x, and 5.0.x through 5.2.x and Pentaho Data Integration (PDI) Suite 4.3.x, 4.4.x, and 5.0.x through 5.2.x does not restrict…
|
CWE-200
Information Exposure
|
CVE-2015-6940
|
2024-11-21 11:35 |
2015-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269890
|
- |
|
adobe google
|
flash_player air android air_sdk air_sdk_\&_compiler
|
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before…
|
NVD-CWE-Other
|
CVE-2015-6682
|
2024-11-21 11:35 |
2015-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|