|
272631
|
3.5 |
LOW
Adjacent
|
qemu fedoraproject novell canonical redhat xen arista
|
qemu fedora suse_linux_enterprise_server suse_linux_enterprise_debuginfo suse_linux_enterprise_desktop suse_linux_enterprise_software_development_kit ubuntu_linux enterprise_linu…
|
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of ser…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2015-6815
|
2024-11-21 11:35 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272632
|
5.5 |
MEDIUM
Local
|
freereprintables
|
articlefr
|
Directory traversal vulnerability in application/templates/amelia/loadjs.php in Free Reprintables ArticleFR 3.0.7 and earlier allows local users to read arbitrary files via the s parameter.
|
CWE-22
Path Traversal
|
CVE-2015-6591
|
2024-11-21 11:35 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272633
|
8.8 |
HIGH
Network
|
magento
|
magento
|
The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.…
|
CWE-20
Improper Input Validation
|
CVE-2015-6497
|
2024-11-21 11:35 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272634
|
7.5 |
HIGH
Network
|
cloudera
|
cloudera_manager
|
There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.
|
CWE-200
Information Exposure
|
CVE-2015-6495
|
2024-11-21 11:35 |
2019-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272635
|
6.1 |
MEDIUM
Network
|
edx
|
edx-platform
|
edx-platform before 2015-09-17 allows XSS via a team name.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6960
|
2024-11-21 11:35 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272636
|
8.8 |
HIGH
Network
|
moxa
|
softcms
|
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6458
|
2024-11-21 11:35 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272637
|
8.8 |
HIGH
Network
|
moxa
|
softcms
|
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6457
|
2024-11-21 11:35 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272638
|
5.4 |
MEDIUM
Network
|
schneider-electric
|
bmxnoc0401_firmware bmxnoe0100_firmware bmxnoe0110_firmware bmxnoe0110h_firmware bmxnor0200h_firmware modicon_m340_bmxp342020_firmware modicon_m340_bmxp342020h_firmware modicon_m…
|
Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, B…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6462
|
2024-11-21 11:35 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272639
|
5.4 |
MEDIUM
Network
|
schneider-electric
|
bmxnoc0401_firmware bmxnoe0100_firmware bmxnoe0110_firmware bmxnoe0110h_firmware bmxnor0200h_firmware modicon_m340_bmxp342020_firmware modicon_m340_bmxp342020h_firmware modicon_m…
|
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP…
|
CWE-20
Improper Input Validation
|
CVE-2015-6461
|
2024-11-21 11:35 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272640
|
5.9 |
MEDIUM
Network
|
atlassian
|
floodlight
|
Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thread crash) via a stat…
|
CWE-362 CWE-476
Race Condition NULL Pointer Dereference
|
CVE-2015-6569
|
2024-11-21 11:35 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|