CVE-2015-7000 to CVE-2015-7999
124 CVEs with public proof-of-concept exploits.
- CVE-2015-70073 PoCsScript Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement for AppleScript…
- CVE-2015-70391 PoCBuffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows remote attackers to…
- CVE-2015-70475 PoCsThe kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges via…
- CVE-2015-70681 PoCIOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary…
- CVE-2015-70771 PoCThe Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service…
- CVE-2015-70781 PoCUse-after-free vulnerability in Hypervisor in Apple OS X before 10.11.2 allows local users to gain privileges via vectors involving VM…
- CVE-2015-70792 PoCsdyld in Apple iOS before 9.2 and tvOS before 9.1 mishandles segment validation, which allows attackers to execute arbitrary code in a…
- CVE-2015-70831 PoCThe kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or…
- CVE-2015-70842 PoCsThe kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges or…
- CVE-2015-71061 PoCThe Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service…
- CVE-2015-71081 PoCThe Bluetooth HCI interface in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of service (memory…
- CVE-2015-71101 PoCThe Disk Images component in Apple OS X before 10.11.2 and tvOS before 9.1 allows local users to gain privileges or cause a denial of…
- CVE-2015-71121 PoCThe IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute…
- CVE-2015-72141 PoCMozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and…
- CVE-2015-72351 PoCMultiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for WordPress allow…
- CVE-2015-72412 PoCsXML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
- CVE-2015-72433 PoCsBuffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
- CVE-2015-72453 PoCsDirectory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to…
- CVE-2015-72462 PoCsD-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the…
- CVE-2015-72472 PoCsD-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account…
- CVE-2015-72481 PoCZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password hashes by reading…
- CVE-2015-72491 PoCZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a…
- CVE-2015-72501 PoCAbsolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote…
- CVE-2015-72511 PoCZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote…
- CVE-2015-72521 PoCCross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote…
- CVE-2015-72541 PoCDirectory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a ..…
- CVE-2015-72571 PoCZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change…
- CVE-2015-72581 PoCZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by…
- CVE-2015-72591 PoCZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and…
- CVE-2015-72932 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
- CVE-2015-729723 PoCsSQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors,…
- CVE-2015-72991 PoCSQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote…
- CVE-2015-73093 PoCsThe theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to…
- CVE-2015-73241 PoCMultiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5…
- CVE-2015-73261 PoCXML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3.
- CVE-2015-73462 PoCsSQL injection vulnerability in ZCMS 1.1.
- CVE-2015-73472 PoCsCross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1.
- CVE-2015-73481 PoCCross-site scripting (XSS) vulnerability in zTree 3.5.19.1 and possibly earlier allows remote attackers to inject arbitrary web script or…
- CVE-2015-73581 PoCThe IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows,…
- CVE-2015-73771 PoCCross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows…
- CVE-2015-73781 PoCPanda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which…
- CVE-2015-73811 PoCMultiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote…
- CVE-2015-73821 PoCSQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute…
- CVE-2015-73874 PoCsZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute…
- CVE-2015-74221 PoCBuffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via unspecified vectors.
- CVE-2015-74503 PoCsKEVSerialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products…
- CVE-2015-74971 PoCHeap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to…
- CVE-2015-75013 PoCsRed Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise…
- CVE-2015-75051 PoCStack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a…
- CVE-2015-75071 PoClibnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color…
- CVE-2015-75081 PoCHeap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a…
- CVE-2015-75101 PoCStack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
- CVE-2015-75151 PoCThe aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a…
- CVE-2015-75451 PoCThe (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and…
- CVE-2015-754713 PoCsMultiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka…
- CVE-2015-75511 PoCThe Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4, as distributed…
- CVE-2015-75561 PoCDeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program.
- CVE-2015-75621 PoCMultiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script…
- CVE-2015-75631 PoCCross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an…
- CVE-2015-75641 PoCMultiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2015-75661 PoCThe clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause…
- CVE-2015-75673 PoCsSQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token"…
- CVE-2015-75682 PoCsSQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials…
- CVE-2015-75692 PoCsSQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via…
- CVE-2015-75702 PoCsMultiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and…
- CVE-2015-75713 PoCsUnrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an…
- CVE-2015-76012 PoCsDirectory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double…
- CVE-2015-76022 PoCsDirectory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in a…
- CVE-2015-76032 PoCsDirectory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via a ..\ (dot dot…
- CVE-2015-76091 PoCSynacor Zimbra Mail Client 8.6 before 8.6.0 Patch 5 has XSS via the error/warning dialog and email body content in Zimbra.
- CVE-2015-76112 PoCsApache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via…
- CVE-2015-76131 PoCRace condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an…
- CVE-2015-76221 PoCAdobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and…
- CVE-2015-76451 PoCKEVAdobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows…
- CVE-2015-76471 PoCAdobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux allows attackers to…
- CVE-2015-76481 PoCAdobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux allows attackers to…
- CVE-2015-76521 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before…
- CVE-2015-76721 PoCCross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).
- CVE-2015-77071 PoCIgnite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to…
- CVE-2015-77093 PoCsThe arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass…
- CVE-2015-77111 PoCCross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script…
- CVE-2015-77141 PoCMultiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to…
- CVE-2015-77151 PoCCross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers…
- CVE-2015-77231 PoCAMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
- CVE-2015-77241 PoCAMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an…
- CVE-2015-77431 PoCXML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary…
- CVE-2015-77441 PoCwolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when…
- CVE-2015-77552 PoCsKEVJuniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15…
- CVE-2015-77653 PoCsZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which…
- CVE-2015-77663 PoCsPGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions…
- CVE-2015-77672 PoCsBuffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of service…
- CVE-2015-77684 PoCsBuffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD command.
- CVE-2015-77801 PoCDirectory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
- CVE-2015-78051 PoCHeap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header…
- CVE-2015-78088 PoCsThe vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection…
- CVE-2015-78231 PoCOpen redirect vulnerability in CMSPages/GetDocLink.ashx in Kentico CMS 8.2 through 8.2.41 allows remote attackers to redirect users to…
- CVE-2015-78481 PoCAn integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted…
- CVE-2015-78551 PoCThe decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of…
- CVE-2015-785719 PoCsSQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2…
- CVE-2015-785819 PoCsSQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors,…
- CVE-2015-78651 PoCnvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358…
- CVE-2015-78711 PoCCrypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
- CVE-2015-78741 PoCBuffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long…
- CVE-2015-78891 PoCThe SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the…
- CVE-2015-78901 PoCMultiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow…
- CVE-2015-78912 PoCsRace condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1)…
- CVE-2015-78922 PoCsStack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in Samsung S6 Edge,…
- CVE-2015-78931 PoCSecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.
- CVE-2015-78941 PoCThe DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allows remote attackers…
- CVE-2015-78951 PoCSamsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
- CVE-2015-78961 PoCLibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and…
- CVE-2015-78971 PoCThe media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9…
- CVE-2015-78981 PoCSamsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
- CVE-2015-79001 PoCInfinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive debugging…
- CVE-2015-79012 PoCsInfinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS…
- CVE-2015-79021 PoCInfinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed login attempts in…
- CVE-2015-79031 PoCSQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated…
- CVE-2015-79041 PoCUnrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote…
- CVE-2015-79441 PoCThe RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before…
- CVE-2015-79451 PoCThe RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before…
- CVE-2015-79841 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware…
- CVE-2015-79851 PoCValve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges…
- CVE-2015-79861 PoCThe index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service…
- CVE-2015-79891 PoCCross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject…