|
272971
|
- |
|
debian xen fedoraproject canonical
|
debian_linux xen fedora ubuntu_linux
|
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2756
|
2024-11-21 11:28 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272972
|
- |
|
ab_google_map_travel_project
|
ab_google_map_travel
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the AB Google Map Travel (AB-MAP) plugin before 4.0 for WordPress allow remote attackers to hijack the authentication of administrators f…
|
CWE-352
Origin Validation Error
|
CVE-2015-2755
|
2024-11-21 11:28 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272973
|
- |
|
synology
|
diskstation_manager
|
The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses that are not link-local, which allows remote attack…
|
CWE-200
Information Exposure
|
CVE-2015-2809
|
2024-11-21 11:28 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272974
|
- |
|
oracle debian redhat suse opensuse canonical fujitsu huawei ibm
|
http_server integrated_lights_out_manager_firmware communications_application_session_controller communications_policy_management debian_linux enterprise_linux_desktop enterprise_li…
|
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to cond…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2015-2808
|
2024-11-21 11:28 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272975
|
- |
|
debian gaia-gis
|
debian_linux freexl
|
The parse_SST function in FreeXL before 1.0.0i allows remote attackers to cause a denial of service (memory consumption) via a crafted shared strings table in a workbook.
|
CWE-20
Improper Input Validation
|
CVE-2015-2776
|
2024-11-21 11:28 |
2015-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272976
|
- |
|
wpml
|
wpml
|
The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actions via a request con…
|
CWE-284
Improper Access Control
|
CVE-2015-2792
|
2024-11-21 11:28 |
2015-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272977
|
- |
|
wpml
|
wpml
|
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted request to sitepress-multilingual-cms/menu/men…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2791
|
2024-11-21 11:28 |
2015-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272978
|
- |
|
foxitsoftware
|
enterprise_reader foxit_reader phantompdf
|
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure o…
|
CWE-20
Improper Input Validation
|
CVE-2015-2790
|
2024-11-21 11:28 |
2015-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272979
|
- |
|
foxitsoftware
|
foxit_reader
|
Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.1 through 7.0.6.1126 allows local users to gain privileges via a Trojan horse p…
|
NVD-CWE-Other
|
CVE-2015-2789
|
2024-11-21 11:28 |
2015-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272980
|
- |
|
php apple redhat opensuse
|
php mac_os_x enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_node_eus …
|
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execu…
|
NVD-CWE-Other
|
CVE-2015-2787
|
2024-11-21 11:28 |
2015-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|