|
272941
|
- |
|
synology
|
download_station
|
Cross-site scripting (XSS) vulnerability in the "Create download task via file upload" feature in Synology Download Station before 3.5-2962 allows remote attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6909
|
2024-11-21 11:35 |
2015-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272942
|
- |
|
openldap apple
|
openldap mac_os_x
|
The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable assertion and application crash) via crafted BER dat…
|
CWE-20
Improper Input Validation
|
CVE-2015-6908
|
2024-11-21 11:35 |
2015-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272943
|
- |
|
siemens
|
ruggedcom_rugged_operating_system
|
Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation protection mechanism via IP traffic.
|
CWE-284
Improper Access Control
|
CVE-2015-6675
|
2024-11-21 11:35 |
2015-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272944
|
- |
|
moxa
|
eds-405a_firmware eds-408a_firmware
|
Cross-site scripting (XSS) vulnerability in the Diagnosis Ping feature in the administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote attackers to i…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6466
|
2024-11-21 11:35 |
2015-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272945
|
- |
|
moxa
|
eds-405a_firmware eds-408a_firmware
|
The GoAhead web server on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to cause a denial of service (reboot) via a crafted URL.
|
NVD-CWE-noinfo
|
CVE-2015-6465
|
2024-11-21 11:35 |
2015-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272946
|
- |
|
moxa
|
eds-405a_firmware eds-408a_firmware
|
The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to bypass a read-only protection mechanism by using Firefox with a w…
|
NVD-CWE-noinfo
|
CVE-2015-6464
|
2024-11-21 11:35 |
2015-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272947
|
- |
|
auto-exchanger
|
auto-exchanger
|
Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests that change a password via a request to signup.php.
|
CWE-352
Origin Validation Error
|
CVE-2015-6827
|
2024-11-21 11:35 |
2015-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272948
|
- |
|
sprymedia
|
datatables
|
Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6584
|
2024-11-21 11:35 |
2015-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272949
|
- |
|
adobe
|
shockwave_player
|
Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6681
|
2024-11-21 11:35 |
2015-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272950
|
- |
|
adobe
|
shockwave_player
|
Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6…
|
NVD-CWE-noinfo
|
CVE-2015-6680
|
2024-11-21 11:35 |
2015-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|