|
272701
|
- |
|
redhat
|
libuser
|
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a de…
|
CWE-20
Improper Input Validation
|
CVE-2015-3245
|
2024-11-21 11:28 |
2015-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272702
|
- |
|
artifex
|
afpl_ghostscript
|
Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier allows remote attackers to cause a denial of service (crash) via a crafted Postscript (ps) file…
|
CWE-189
Numeric Errors
|
CVE-2015-3228
|
2024-11-21 11:28 |
2015-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272703
|
- |
|
yodobashi
|
yodobashi
|
The Yodobashi application 1.2.1.0 and earlier for Android allows remote attackers to execute arbitrary Java methods, and consequently obtain sensitive information or execute OS commands, via a crafte…
|
CWE-200 CWE-78
Information Exposure OS Command
|
CVE-2015-2980
|
2024-11-21 11:28 |
2015-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272704
|
- |
|
sierrawireless
|
aleos
|
Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtain administrative access via a (1) SSH or (2) TELNE…
|
CWE-200
Information Exposure
|
CVE-2015-2897
|
2024-11-21 11:28 |
2015-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272705
|
6.0 |
MEDIUM
Local
|
dell
|
bios
|
The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a B…
|
NVD-CWE-noinfo
|
CVE-2015-2890
|
2024-11-21 11:28 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272706
|
- |
|
chiyu
|
bf-660c
|
Chiyu BF-660C fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) modify communication configuration settings via a request to net.htm, a different …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2871
|
2024-11-21 11:28 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272707
|
- |
|
chiyutw
|
bf-630 bf-630w bf-660c
|
Cross-site scripting (XSS) vulnerability on Chiyu BF-630, BF-630W, and BF-660C fingerprint access-control devices allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2870
|
2024-11-21 11:28 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272708
|
- |
|
webservice-dic
|
yoyaku
|
Webservice-DIC yoyaku_v41 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2015-2979
|
2024-11-21 11:28 |
2015-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272709
|
- |
|
webservice-dic
|
yoyaku
|
Webservice-DIC yoyaku_v41 allows remote attackers to bypass authentication and complete a conference-room reservation via unspecified vectors, as demonstrated by an "unintentional reservation."
|
CWE-287
Improper Authentication
|
CVE-2015-2978
|
2024-11-21 11:28 |
2015-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272710
|
- |
|
webservice-dic
|
yoyaku
|
Webservice-DIC yoyaku_v41 allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2015-2977
|
2024-11-21 11:28 |
2015-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|