|
270091
|
6.9 |
MEDIUM
Network
|
progress
|
whatsup_gold
|
Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to inject arbitrary web script or HTML via (1) an SNMP OID object, (2) an SNMP trap mes…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6005
|
2024-11-21 11:34 |
2015-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270092
|
5.9 |
MEDIUM
Network
|
cisco
|
jabber
|
Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSC…
|
CWE-200
Information Exposure
|
CVE-2015-6409
|
2024-11-21 11:34 |
2015-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270093
|
6.5 |
MEDIUM
Adjacent
|
cisco
|
ios_xe
|
Cisco IOS XE 16.1.1 allows remote attackers to cause a denial of service (device reload) via a packet with the 00-00-00-00-00-00 source MAC address, aka Bug ID CSCux48405.
|
CWE-399
Resource Management Errors
|
CVE-2015-6431
|
2024-11-21 11:34 |
2015-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270094
|
- |
|
cisco
|
ios ios_xe
|
The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection termination) via a crafted IKEv1 packet to a…
|
CWE-19
Data Processing Errors
|
CVE-2015-6429
|
2024-11-21 11:34 |
2015-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270095
|
- |
|
cisco
|
dpq3925_8x4_docsis_3.0_wireless_residential_gateway_with_embedded_digital_voice_adapter
|
Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958.
|
CWE-200
Information Exposure
|
CVE-2015-6428
|
2024-11-21 11:34 |
2015-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270096
|
- |
|
cisco
|
firesight_system_software
|
Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL session that is mishandled after decryption, aka …
|
CWE-254
7PK - Security Features
|
CVE-2015-6427
|
2024-11-21 11:34 |
2015-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270097
|
- |
|
cisco
|
prime_network_services_controller
|
Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitrary commands via additional parameters to an unspecified command, aka Bug ID CS…
|
CWE-20
Improper Input Validation
|
CVE-2015-6426
|
2024-11-21 11:34 |
2015-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270098
|
- |
|
cisco
|
application_policy_infrastructure_controller
|
The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspeci…
|
CWE-255
Credentials Management
|
CVE-2015-6424
|
2024-11-21 11:34 |
2015-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270099
|
- |
|
cisco
|
unified_communications_manager
|
The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service (subsystem outage) via invalid session …
|
CWE-399
Resource Management Errors
|
CVE-2015-6425
|
2024-11-21 11:34 |
2015-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270100
|
- |
|
apache
|
commons_collections
|
Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Device…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2015-6420
|
2024-11-21 11:34 |
2015-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|