|
270111
|
9.8 |
CRITICAL
Network
|
totolink
|
a850r-v1_firmware f1-v2_firmware f2-v1_firmware n150rt-v2_firmware n151rt-v2_firmware n300rh-v2_firmware n300rh-v3_firmware n300rt-v2_firmware
|
An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution in the management interface via the formSysCmd s…
|
NVD-CWE-noinfo
|
CVE-2015-9551
|
2024-11-21 11:40 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270112
|
7.5 |
HIGH
Network
|
totolink
|
a850r-v1_firmware f1-v2_firmware f2-v1_firmware n150rt-v2_firmware n151rt-v2_firmware n300rh-v2_firmware n300rh-v3_firmware n300rt-v2_firmware
|
An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. By sending a specific hel,xasf packet to the WAN interface, it is possible to o…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2015-9550
|
2024-11-21 11:40 |
2020-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270113
|
6.1 |
MEDIUM
Network
|
ocportal
|
ocportal
|
A reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME field to data/emoticons.php.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9549
|
2024-11-21 11:40 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270114
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compressed file that has a large size when uncompressed.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-9548
|
2024-11-21 11:40 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270115
|
7.5 |
HIGH
Network
|
google
|
android
|
An issue was discovered on Samsung mobile devices with JBP(4.3) and KK(4.4.2) software. Because the READ_LOGS permission is mishandled, sensitive information is disclosed in a world-readable copy of …
|
CWE-200
Information Exposure
|
CVE-2015-9547
|
2024-11-21 11:40 |
2020-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270116
|
4.8 |
MEDIUM
Network
|
google
|
android
|
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker c…
|
CWE-22
Path Traversal
|
CVE-2015-9546
|
2024-11-21 11:40 |
2020-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270117
|
7.1 |
HIGH
Local
|
cross_domain_local_storage_project
|
cross_domain_local_storage
|
An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not implement any validation of the origin of web messages. Remote attackers who can e…
|
CWE-20
Improper Input Validation
|
CVE-2015-9545
|
2024-11-21 11:40 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270118
|
7.1 |
HIGH
Local
|
cross_domain_local_storage_project
|
cross_domain_local_storage
|
An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any validation of the origin of web messages. Remote attac…
|
CWE-20
Improper Input Validation
|
CVE-2015-9544
|
2024-11-21 11:40 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270119
|
7.5 |
HIGH
Network
|
freeradius debian canonical
|
pam_radius debian_linux ubuntu_linux
|
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could …
|
CWE-787
Out-of-bounds Write
|
CVE-2015-9542
|
2024-11-21 11:40 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270120
|
3.3 |
LOW
Local
|
openstack
|
nova
|
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs …
|
CWE-200
Information Exposure
|
CVE-2015-9543
|
2024-11-21 11:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|