|
270841
|
- |
|
bittorrent utorrent
|
bittorrent utorrent
|
BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol.
|
CWE-77
Command Injection
|
CVE-2015-5474
|
2024-11-21 11:33 |
2015-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270842
|
- |
|
websense
|
content_gateway
|
Stack-based buffer overflow in the handle_debug_network function in the manager in Websense Content Gateway before 8.0.0 HF02 allows remote administrators to cause a denial of service (crash) via a c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5718
|
2024-11-21 11:33 |
2015-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270843
|
- |
|
canonical debian apple htacg
|
ubuntu_linux debian_linux mac_os_x watchos iphone_os tidy
|
The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5523
|
2024-11-21 11:33 |
2015-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270844
|
- |
|
htacg canonical debian apple
|
tidy ubuntu_linux debian_linux mac_os_x watchos iphone_os
|
Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an hre…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5522
|
2024-11-21 11:33 |
2015-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270845
|
- |
|
wordpress debian
|
wordpress debian_linux
|
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscribe…
|
CWE-284
Improper Access Control
|
CVE-2015-5623
|
2024-11-21 11:33 |
2015-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270846
|
- |
|
wordpress debian
|
wordpress debian_linux
|
Cross-site scripting (XSS) vulnerability in WordPress before 4.2.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the Author or Contributor role to place a cra…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5622
|
2024-11-21 11:33 |
2015-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270847
|
- |
|
openbsd
|
openssh
|
The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it ea…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5600
|
2024-11-21 11:33 |
2015-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270848
|
- |
|
siemens
|
ruggedcom_rugged_operating_system ruggedcom_rox_ii_firmware
|
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2015-5537
|
2024-11-21 11:33 |
2015-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270849
|
- |
|
chiyutw
|
bf-630 bf-630w
|
Chiyu BF-630 and BF-630W fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) modify (a) Voice Time Set configuration settings via a request to voice…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5618
|
2024-11-21 11:33 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270850
|
- |
|
isc
|
bind
|
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
|
CWE-19
Data Processing Errors
|
CVE-2015-5477
|
2024-11-21 11:33 |
2015-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|