CVE-2015-8000 to CVE-2015-8999
116 CVEs with public proof-of-concept exploits.
- CVE-2015-80371 PoCMultiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow…
- CVE-2015-80381 PoCMultiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow…
- CVE-2015-80412 PoCsMultiple integer overflows in the NDEF record parser in hostapd before 2.5 and wpa_supplicant before 2.5 allow remote attackers to cause a…
- CVE-2015-80431 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before…
- CVE-2015-80441 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before…
- CVE-2015-80461 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before…
- CVE-2015-80481 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-80801 PoCInteger overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent…
- CVE-2015-80882 PoCsHeap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7-TL10 before…
- CVE-2015-81037 PoCsThe Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted…
- CVE-2015-82391 PoCThe SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called…
- CVE-2015-82495 PoCsThe FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary…
- CVE-2015-82551 PoCAXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
- CVE-2015-82562 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
- CVE-2015-82572 PoCsThe devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in…
- CVE-2015-82581 PoCAXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving…
- CVE-2015-82611 PoCThe DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects,…
- CVE-2015-82701 PoCThe AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a denial of service (invalid pointer…
- CVE-2015-82711 PoCThe AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.
- CVE-2015-82721 PoCRTMPDump 2.4 allows remote attackers to trigger a denial of service (NULL pointer dereference and process crash).
- CVE-2015-82771 PoCMultiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote…
- CVE-2015-82791 PoCWeb Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to read arbitrary files via a request to an unspecified PHP…
- CVE-2015-82822 PoCsSeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.
- CVE-2015-82832 PoCsDirectory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.
- CVE-2015-82842 PoCsSeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
- CVE-2015-82851 PoCThe webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
- CVE-2015-82981 PoCMultiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL…
- CVE-2015-82993 PoCsBuffer overflow in the Group messages monitor (Falcon) in KNX ETS 4.1.5 (Build 3246) allows remote attackers to execute arbitrary code via…
- CVE-2015-83091 PoCDirectory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value"…
- CVE-2015-83151 PoCThe ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a…
- CVE-2015-83491 PoCCross-site scripting (XSS) vulnerability in SourceBans before 2.0 pre-alpha allows remote attackers to inject arbitrary web script or HTML…
- CVE-2015-83501 PoCMultiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to…
- CVE-2015-83517 PoCsPHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled,…
- CVE-2015-83521 PoCDirectory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot…
- CVE-2015-83531 PoCCross-site scripting (XSS) vulnerability in the Role Scoper plugin before 1.3.67 for WordPress allows remote attackers to inject arbitrary…
- CVE-2015-83541 PoCCross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to…
- CVE-2015-83562 PoCsMultiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated users to execute…
- CVE-2015-83571 PoCDirectory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary…
- CVE-2015-83581 PoCDirectory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and…
- CVE-2015-83681 PoCntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and…
- CVE-2015-83961 PoCInteger overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots…
- CVE-2015-83981 PoCCross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or…
- CVE-2015-83994 PoCsAtlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1)…
- CVE-2015-84101 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84111 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84121 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84131 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84201 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84211 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84221 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84231 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84241 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84251 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84261 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84271 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84281 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84291 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84301 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84311 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84341 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before…
- CVE-2015-84761 PoCMultiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in…
- CVE-2015-85081 PoCCross-site scripting (XSS) vulnerability in showdependencygraph.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before…
- CVE-2015-85091 PoCTemplate.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly…
- CVE-2015-85221 PoCBuffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute…
- CVE-2015-85431 PoCThe networking implementation in the Linux kernel through 4.3.3, as used in Android and other products, does not validate protocol…
- CVE-2015-85501 PoCXen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or…
- CVE-2015-85562 PoCsLocal privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
- CVE-2015-856218 PoCsJoomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via…
- CVE-2015-85661 PoCThe Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspecified session values.
- CVE-2015-86081 PoCThe VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and…
- CVE-2015-86122 PoCsThe EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users to gain…
- CVE-2015-86171 PoCFormat string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers…
- CVE-2015-86201 PoCHeap-based buffer overflow in the Avast virtualization driver (aswSnx.sys) in Avast Internet Security, Pro Antivirus, Premier, and Free…
- CVE-2015-86341 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before…
- CVE-2015-86351 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before…
- CVE-2015-86361 PoCAdobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR…
- CVE-2015-86441 PoCAdobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR…
- CVE-2015-86607 PoCsThe ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which…
- CVE-2015-86641 PoCInteger overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106…
- CVE-2015-86681 PoCHeap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote…
- CVE-2015-87031 PoCZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to…
- CVE-2015-87101 PoCThe htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service…
- CVE-2015-87231 PoCThe AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before…
- CVE-2015-87241 PoCThe AirPDcapDecryptWPABroadcastKey function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x…
- CVE-2015-87251 PoCThe dissect_diameter_base_framed_ipv6_prefix function in epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.12.x…
- CVE-2015-87261 PoCwiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate certain signature and…
- CVE-2015-87271 PoCThe dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before…
- CVE-2015-87281 PoCThe Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A dissector and (2) epan/dissectors/packet-gsm_a_common.c in…
- CVE-2015-87291 PoCThe ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does…
- CVE-2015-87301 PoCepan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the number…
- CVE-2015-87311 PoCThe dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x…
- CVE-2015-87321 PoCThe dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee-zcl-general.c in the ZigBee ZCL dissector in Wireshark…
- CVE-2015-87331 PoCThe ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before…
- CVE-2015-87351 PoCThe get_value function in epan/dissectors/packet-btatt.c in the Bluetooth Attribute (aka BT ATT) dissector in Wireshark 2.0.x before 2.0.1…
- CVE-2015-87361 PoCThe mp2t_find_next_pcr function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not reserve memory for a…
- CVE-2015-87391 PoCThe ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI dissector in Wireshark 2.0.x before 2.0.1 improperly attempts…
- CVE-2015-87401 PoCThe dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not…
- CVE-2015-87511 PoCInteger overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted…
- CVE-2015-87701 PoCDirectory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x…
- CVE-2015-87801 PoCSamsung wssyncmlnps before 2015-10-31 allows directory traversal in a Kies restore, aka ZipFury.
- CVE-2015-88131 PoCThe Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote…
- CVE-2015-88311 PoCCross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web…
- CVE-2015-88321 PoCMultiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with…
- CVE-2015-88341 PoCCross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary…
- CVE-2015-88411 PoCHeap-based buffer overflow in the Archive support module in ESET NOD32 before update 11861 allows remote attackers to execute arbitrary…
- CVE-2015-88581 PoCThe uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a…
- CVE-2015-88611 PoCThe handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a…
- CVE-2015-88731 PoCStack consumption vulnerability in Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote…
- CVE-2015-89151 PoCbsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file.
- CVE-2015-89251 PoCThe readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of…
- CVE-2015-89531 PoCfs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users to cause a denial of…
- CVE-2015-89661 PoCarch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 4.4 allows local users to gain privileges via a crafted (1) F_OFD_GETLK, (2)…
- CVE-2015-89681 PoCgit-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a…
- CVE-2015-89691 PoCgit-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by…
- CVE-2015-89792 PoCsStack-based buffer overflow in the parsePresentationContext function in storescp in DICOM dcmtk-3.6.0 and earlier allows remote attackers…
- CVE-2015-89942 PoCsAn issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache enabled. With 5.x…