|
269721
|
7.7 |
HIGH
Network
|
ntp siemens netapp debian
|
ntp tim_4r-ie_firmware tim_4r-ie_dnp3_firmware oncommand_balance clustered_data_ontap debian_linux
|
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via a…
|
CWE-287
Improper Authentication
|
CVE-2015-7974
|
2024-11-21 11:37 |
2016-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269722
|
5.9 |
MEDIUM
Network
|
wolfssl opensuse mariadb
|
wolfssl leap opensuse mariadb
|
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimization…
|
NVD-CWE-noinfo
|
CVE-2015-7744
|
2024-11-21 11:37 |
2016-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269723
|
7.3 |
HIGH
Network
|
hospira
|
communication_engine lifecare_pca_infusion_system
|
Stack-based buffer overflow in Hospira Communication Engine (CE) before 1.2 in LifeCare PCA Infusion System 5.07, Plum A+ Infusion System 13.40, and Plum A+3 Infusion System 13.40 allows remote attac…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7909
|
2024-11-21 11:37 |
2016-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269724
|
3.7 |
LOW
Network
|
netapp
|
data_ontap
|
NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive volume information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-7886
|
2024-11-21 11:37 |
2016-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269725
|
3.7 |
LOW
Network
|
f5
|
big-ip_analytics big-ip_application_acceleration_manager big-ip_link_controller big-ip_advanced_firewall_manager big-ip_policy_enforcement_manager big-ip_local_traffic_manager big-i…
|
BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 12.0.0 before HF1, when the TCP profile for a virtual server is configured with Congestion Metrics Cache enabled, allow remote atta…
|
CWE-20
Improper Input Validation
|
CVE-2015-7759
|
2024-11-21 11:37 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269726
|
7.8 |
HIGH
Local
|
huawei
|
p8_firmware mate_7_firmware
|
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7-TL10 before MT7-TL10C00B354, MT7-TL00 before MT7-TL00C01B354, and MT7-CL00 bef…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-8088
|
2024-11-21 11:37 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269727
|
6.1 |
MEDIUM
Network
|
ssp-europe
|
secure_data_space
|
Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to api/v3/public/shar…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7706
|
2024-11-21 11:37 |
2016-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269728
|
9.6 |
CRITICAL
Network
|
unitronics
|
visilogic_oplc_ide
|
Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary code via a long vlp filename.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7939
|
2024-11-21 11:37 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269729
|
9.8 |
CRITICAL
Network
|
advantech
|
eki-1321_series_firmware eki-1322_series_firmware
|
Advantech EKI-132x devices with firmware before 2015-12-31 allow remote attackers to bypass authentication via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2015-7938
|
2024-11-21 11:37 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269730
|
5.9 |
MEDIUM
Network
|
mozilla opensuse canonical
|
network_security_services leap opensuse firefox ubuntu_linux
|
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in T…
|
CWE-19
Data Processing Errors
|
CVE-2015-7575
|
2024-11-21 11:37 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|