|
272181
|
3.3 |
LOW
Local
|
opensuse gummi_project
|
leap opensuse gummi
|
Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .to…
|
CWE-59
Link Following
|
CVE-2015-7758
|
2024-11-21 11:37 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272182
|
8.1 |
HIGH
Network
|
juniper
|
screenos
|
Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or execute arbitrary code via crafted SSH negotiation.
|
CWE-20
Improper Input Validation
|
CVE-2015-7754
|
2024-11-21 11:37 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272183
|
7.5 |
HIGH
Network
|
nodejs
|
node.js
|
Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (unc…
|
CWE-17
Code
|
CVE-2015-8027
|
2024-11-21 11:37 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272184
|
5.8 |
MEDIUM
Network
|
corega
|
cg-wlncm4g_firmware
|
Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) via crafted queries.
|
CWE-20
Improper Input Validation
|
CVE-2015-7794
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272185
|
5.8 |
MEDIUM
Network
|
corega
|
cg-wlbaragm_firmware
|
Corega CG-WLBARAGM devices provide an open proxy service, which allows remote attackers to trigger outbound network traffic via unspecified vectors.
|
CWE-17
Code
|
CVE-2015-7793
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272186
|
9.8 |
CRITICAL
Network
|
corega
|
cg-wlbargs_firmware
|
Corega CG-WLBARGS devices allow remote attackers to perform administrative operations via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7792
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272187
|
6.1 |
MEDIUM
Network
|
asus
|
wl-330nul_firmware
|
Cross-site scripting (XSS) vulnerability on ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7790
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272188
|
4.3 |
MEDIUM
Adjacent
|
asus
|
wl-33nul_firmware wl-330nul
|
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to cause a denial of service via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2015-7789
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272189
|
7.3 |
HIGH
Network
|
asus
|
wl-330nul_firmware
|
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to execute arbitrary commands via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7788
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272190
|
4.3 |
MEDIUM
Adjacent
|
asus
|
wl-330nul_firmware
|
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to discover the WPA2-PSK passphrase via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-7787
|
2024-11-21 11:37 |
2015-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|