|
272291
|
- |
|
apple
|
iphone_os watchos tvos mac_os_x
|
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to cause a denial of service via a crafted app, a different vulnerability than CVE-20…
|
NVD-CWE-noinfo
|
CVE-2015-7040
|
2024-11-21 11:36 |
2015-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272292
|
- |
|
apple
|
tvos watchos iphone_os mac_os_x
|
Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vuln…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7039
|
2024-11-21 11:36 |
2015-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272293
|
- |
|
apple
|
tvos iphone_os mac_os_x watchos
|
Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to execute arbitrary code via a crafted package, a different vuln…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7038
|
2024-11-21 11:36 |
2015-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272294
|
- |
|
apple
|
iphone_os
|
Directory traversal vulnerability in Mobile Backup in Photos in Apple iOS before 9.2 allows attackers to read arbitrary files via a crafted pathname.
|
CWE-22
Path Traversal
|
CVE-2015-7037
|
2024-11-21 11:36 |
2015-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272295
|
- |
|
apple
|
watchos iphone_os tvos mac_os_x
|
AppSandbox in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 mishandles hard links, which allows attackers to bypass Contacts access revocation via a crafted app.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7001
|
2024-11-21 11:36 |
2015-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272296
|
- |
|
ztree_project
|
ztree
|
Cross-site scripting (XSS) vulnerability in zTree 3.5.19.1 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter to demo/en/asyncData/getNodesForBig…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7348
|
2024-11-21 11:36 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272297
|
- |
|
csl_dualcom
|
gprs_cs2300-r_firmware
|
CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 allow remote attackers to modify the configuration via a command in an SMS message, as demonstrated by a "4 2" command.
|
CWE-254
7PK - Security Features
|
CVE-2015-7288
|
2024-11-21 11:36 |
2015-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272298
|
- |
|
csl_dualcom
|
gprs_cs2300-r_firmware
|
CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 use the same 001984 default PIN across different customers' installations, which allows remote attackers to execute commands by lever…
|
CWE-255
Credentials Management
|
CVE-2015-7287
|
2024-11-21 11:36 |
2015-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272299
|
- |
|
csl_dualcom
|
gprs_cs2300-r_firmware
|
CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 rely on a polyalphabetic substitution cipher with hardcoded keys, which makes it easier for remote attackers to defeat a cryptographi…
|
CWE-310
Cryptographic Issues
|
CVE-2015-7286
|
2024-11-21 11:36 |
2015-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272300
|
- |
|
csl_dualcom
|
gprs_cs2300-r_firmware
|
CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Center (ARC) servers, which allows man-in-the-middle attackers to bypass intended …
|
CWE-287
Improper Authentication
|
CVE-2015-7285
|
2024-11-21 11:36 |
2015-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|