|
274291
|
7.8 |
HIGH
Local
|
hancom
|
hangul_word_processor
|
hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type confusion" via an HWPX file containing a crafted para text ta…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6585
|
2024-11-21 11:35 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274292
|
5.4 |
MEDIUM
Network
|
vindula
|
vindula
|
Cross-site scripting (XSS) vulnerability in Vindula 1.9.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6959
|
2024-11-21 11:35 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274293
|
6.1 |
MEDIUM
Network
|
igcb
|
intellect_digital_core
|
Cross-site scripting (XSS) vulnerability in Intellect Design Arena Intellect Core banking software.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6540
|
2024-11-21 11:35 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274294
|
7.8 |
HIGH
Local
|
paloaltonetworks
|
pan-os
|
Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.
|
CWE-94
Code Injection
|
CVE-2015-6531
|
2024-11-21 11:35 |
2017-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274295
|
8.1 |
HIGH
Network
|
pgbouncer
|
pgbouncer
|
PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.
|
CWE-287
Improper Authentication
|
CVE-2015-6817
|
2024-11-21 11:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274296
|
7.5 |
HIGH
Network
|
huawei
|
wlan_acu2_firmware wlan_ac6005_firmware wlan_ac6605_firmware
|
The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote attackers to obtain sensitive information by leveraging failure to restrict proces…
|
CWE-200
Information Exposure
|
CVE-2015-6586
|
2024-11-21 11:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274297
|
8.8 |
HIGH
Network
|
wolfcms
|
wolf_cms
|
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" …
|
CWE-20
Improper Input Validation
|
CVE-2015-6568
|
2024-11-21 11:35 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274298
|
8.8 |
HIGH
Network
|
wolfcms
|
wolf_cms
|
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exp…
|
CWE-20
Improper Input Validation
|
CVE-2015-6567
|
2024-11-21 11:35 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274299
|
9.8 |
CRITICAL
Network
|
inspircd debian
|
inspircd debian_linux
|
Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This issue exists as an additional issue from an incomplet…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6674
|
2024-11-21 11:35 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274300
|
5.9 |
MEDIUM
Network
|
edx
|
edx-platform
|
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveragi…
|
CWE-200
Information Exposure
|
CVE-2015-6671
|
2024-11-21 11:35 |
2017-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|