|
274041
|
9.8 |
CRITICAL
Network
|
gynoii
|
gcw-1010 gpw-1025 gcw-1020
|
Gynoii has a password of guest for the backdoor guest account and a password of 12345 for the backdoor admin account.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2015-2881
|
2024-11-21 11:28 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274042
|
8.8 |
HIGH
Network
|
trendnet
|
tv-ip743sic
|
TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account.
|
CWE-287
Improper Authentication
|
CVE-2015-2880
|
2024-11-21 11:28 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274043
|
3.3 |
LOW
Local
|
linux redhat
|
linux_kernel enterprise_linux
|
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other …
|
CWE-200
Information Exposure
|
CVE-2015-2877
|
2024-11-21 11:28 |
2017-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274044
|
9.8 |
CRITICAL
Network
|
apache
|
storm
|
The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3188
|
2024-11-21 11:28 |
2017-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274045
|
9.8 |
CRITICAL
Network
|
trane
|
comfortlink_ii_firmware
|
An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can connect to the DSS service on the Trane ComfortLink II…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2868
|
2024-11-21 11:28 |
2017-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274046
|
9.8 |
CRITICAL
Network
|
trane
|
comfortlink_ii_firmware
|
A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2015-2867
|
2024-11-21 11:28 |
2017-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274047
|
7.5 |
HIGH
Network
|
pcre ibm
|
pcre2 pcre powerkvm
|
PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expr…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3217
|
2024-11-21 11:28 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274048
|
9.8 |
CRITICAL
Network
|
pcre
|
pcre2 pcre
|
Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)…
|
CWE-787
Out-of-bounds Write
|
CVE-2015-3210
|
2024-11-21 11:28 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274049
|
5.5 |
MEDIUM
Local
|
pivotal_software vmware fedoraproject
|
spring_framework fedora
|
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of servi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3192
|
2024-11-21 11:28 |
2016-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274050
|
5.9 |
MEDIUM
Network
|
oracle mariadb fedoraproject debian redhat php
|
mysql mysql_connector\/c mariadb fedora debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_eus enterprise_linux_ser…
|
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle atta…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-3152
|
2024-11-21 11:28 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|