7.5
    High

    CVE-2015-8258

    Last Modified: 17 Mar 2017

    AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability."

    Source:Orwelllabs
    Published:10 Apr 2017
    8.8
    High

    CVE-2015-8257

    Last Modified: 29 Jul 2016

    The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.shtml.

    Source:Orwelllabs
    Published:2 May 2017
    6.1
    Medium

    CVE-2015-8256

    Last Modified: 11 Apr 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.

    Source:Orwelllabs
    Published:17 Apr 2017
    8.8
    High

    CVE-2015-8255

    Last Modified: 17 Mar 2017

    AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.

    Source:Orwelllabs
    Published:10 Apr 2017
    9.8
    Critical

    CVE-2015-8249

    Last Modified: 15 Dec 2015

    The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.

    Source:Metasploit
    Published:27 Sept 2017
    7
    High

    CVE-2015-8239

    Last Modified: 20 Apr 2025

    The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.

    Published:9 Nov 2015
    9.8
    Critical

    CVE-2015-8103

    Last Modified: 15 Dec 2015

    The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a problematic webapps/ROOT/WEB-INF/lib/commons-collections-*.jar file and the "Groovy variant in 'ysoserial'".

    Source:Metasploit
    Published:11 Nov 2015
    7.8
    High

    CVE-2015-8088

    Last Modified: 19 Mar 2018

    Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7-TL10 before MT7-TL10C00B354, MT7-TL00 before MT7-TL00C01B354, and MT7-CL00 before MT7-CL00C92B354 and P8 phones with software GRA-TL00 before GRA-TL00C01B220SP01, GRA-CL00 before GRA-CL00C92B220, GRA-CL10 before GRA-CL10C92B220, GRA-UL00 before GRA-UL00C00B220, and GRA-UL10 before GRA-UL10C00B220 allows attackers to cause a denial of service (reboot) or execute arbitrary code via a crafted application.

    Source:pray3r
    Published:12 Jan 2016
    10
    Critical

    CVE-2015-8048

    Last Modified: 1 Apr 2016

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015-8068, CVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401, CVE-2015-8402, CVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406, CVE-2015-8410, CVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414, CVE-2015-8420, CVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424, CVE-2015-8425, CVE-2015-8426, CVE-2015-8427, CVE-2015-8428, CVE-2015-8429, CVE-2015-8430, CVE-2015-8431, CVE-2015-8432, CVE-2015-8433, CVE-2015-8434, CVE-2015-8435, CVE-2015-8436, CVE-2015-8437, CVE-2015-8441, CVE-2015-8442, CVE-2015-8447, CVE-2015-8448, CVE-2015-8449, CVE-2015-8450, CVE-2015-8452, and CVE-2015-8454.

    Source:Google Security Research
    Published:8 Dec 2015
    10
    Critical

    CVE-2015-8046

    Last Modified: 17 Dec 2015

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-7651, CVE-2015-7652, CVE-2015-7653, CVE-2015-7654, CVE-2015-7655, CVE-2015-7656, CVE-2015-7657, CVE-2015-7658, CVE-2015-7660, CVE-2015-7661, CVE-2015-7663, CVE-2015-8042, CVE-2015-8043, and CVE-2015-8044.

    Source:Google Security Research
    Published:10 Nov 2015
    10
    Critical

    CVE-2015-8044

    Last Modified: 17 Dec 2015

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-7651, CVE-2015-7652, CVE-2015-7653, CVE-2015-7654, CVE-2015-7655, CVE-2015-7656, CVE-2015-7657, CVE-2015-7658, CVE-2015-7660, CVE-2015-7661, CVE-2015-7663, CVE-2015-8042, CVE-2015-8043, and CVE-2015-8046.

    Source:Google Security Research
    Published:10 Nov 2015
    10
    Critical

    CVE-2015-8043

    Last Modified: 17 Dec 2015

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-7651, CVE-2015-7652, CVE-2015-7653, CVE-2015-7654, CVE-2015-7655, CVE-2015-7656, CVE-2015-7657, CVE-2015-7658, CVE-2015-7660, CVE-2015-7661, CVE-2015-7663, CVE-2015-8042, CVE-2015-8044, and CVE-2015-8046.

    Source:Google Security Research
    Published:10 Nov 2015
    4.3
    Medium

    CVE-2015-8038

    Last Modified: 25 Sept 2015

    Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) sharedjobmanager or (2) SOMServiceObjDialog.

    Source:hyp3rlinx
    Published:2 Nov 2015
    4.3
    Medium

    CVE-2015-8037

    Last Modified: 25 Sept 2015

    Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager before 5.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SOMVpnSSLPortalDialog or (2) FGDMngUpdHistory.

    Source:hyp3rlinx
    Published:2 Nov 2015
    7.5
    High

    CVE-2015-7986

    Last Modified: 28 Jan 2016

    The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTTP request, aka SAP Security Note 2197428.

    Source:ERPScan
    Published:27 Oct 2015
    7.2
    High

    CVE-2015-7985

    Last Modified: 12 Apr 2025

    Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan horse steam.exe file.

    Source:MrDoug
    Published:24 Nov 2015
    6.8
    Medium

    CVE-2015-7984

    Last Modified: 19 Nov 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities in Horde before 5.2.8, Horde Groupware before 5.2.11, and Horde Groupware Webmail Edition before 5.2.11 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary (1) commands via the cmd parameter to admin/cmdshell.php, (2) SQL queries via the sql parameter to admin/sqlshell.php, or (3) PHP code via the php parameter to admin/phpshell.php.

    Source:High-Tech Bridge SA
    Published:19 Nov 2015
    7.5
    High

    CVE-2015-7945

    Last Modified: 5 Jan 2016

    The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2 allows remote attackers to obtain the DRBD secret via instance information job results.

    Source:Pierre Kim
    Published:18 Aug 2017
    7.5
    High

    CVE-2015-7944

    Last Modified: 5 Jan 2016

    The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2, when used in SSL mode, allows remote attackers to cause a denial of service (resource consumption) via SSL parameter renegotiation.

    Source:Pierre Kim
    Published:18 Aug 2017
    6.5
    Medium

    CVE-2015-7904

    Last Modified: 28 Sept 2015

    Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary JSP code via vectors involving an upload of an image file.

    Source:LiquidWorm
    Published:28 Oct 2015
    6.5
    Medium

    CVE-2015-7903

    Last Modified: 28 Sept 2015

    SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Source:LiquidWorm
    Published:28 Oct 2015
    5
    Medium

    CVE-2015-7902

    Last Modified: 28 Sept 2015

    Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed login attempts in unspecified circumstances, which allows remote attackers to obtain sensitive information via a series of requests.

    Source:LiquidWorm
    Published:28 Oct 2015
    6.5
    Medium

    CVE-2015-7901

    Last Modified: 13 Sept 2017

    Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

    Source:James Fitts
    Published:28 Oct 2015
    4.3
    Medium

    CVE-2015-7900

    Last Modified: 28 Sept 2015

    Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive debugging information by entering a crafted URL to trigger an exception, and then visiting a certain status page.

    Source:LiquidWorm
    Published:28 Oct 2015
    5.5
    Medium

    CVE-2015-7898

    Last Modified: 3 Nov 2015

    Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

    Source:Google Security Research
    Published:27 Jun 2017
    7.5
    High

    CVE-2015-7897

    Last Modified: 3 Nov 2015

    The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges or cause a denial of service (memory corruption) via a crafted BMP image file.

    Source:Google Security Research
    Published:16 Nov 2015
    6.5
    Medium

    CVE-2015-7896

    Last Modified: 3 Nov 2015

    LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file.

    Source:Google Security Research
    Published:24 Aug 2017
    5.5
    Medium

    CVE-2015-7895

    Last Modified: 3 Nov 2015

    Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

    Source:Google Security Research
    Published:27 Jun 2017
    8.8
    High

    CVE-2015-7894

    Last Modified: 3 Nov 2015

    The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allows remote attackers to cause a denial of service (segmentation fault and process crash) and execute arbitrary code via a crafted JPG.

    Source:Google Security Research
    Published:9 Aug 2017
    8.8
    High

    CVE-2015-7893

    Last Modified: 28 Oct 2015

    SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.

    Source:Google Security Research
    Published:11 Apr 2017
    7.8
    High

    CVE-2015-7892

    Last Modified: 28 Oct 2017

    Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in Samsung S6 Edge, allows local users to have unspecified impact via a large data.buf_out.num_planes value in an ioctl call.

    Source:Google Security Research
    Published:9 Dec 2019
    7
    High

    CVE-2015-7891

    Last Modified: 28 Oct 2015

    Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows local users to trigger memory errors by leveraging definition of g2d_lock and g2d_unlock lock macros as no-ops, aka SVE-2015-4598.

    Source:Google Security Research
    Published:2 Aug 2017
    5.5
    Medium

    CVE-2015-7890

    Last Modified: 28 Oct 2017

    Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size parameter.

    Source:Google Security Research
    Published:12 Feb 2020
    5.5
    Medium

    CVE-2015-7889

    Last Modified: 28 Oct 2015

    The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with knowledge of the local email address to obtain sensitive information via a crafted application that sends a crafted intent.

    Source:Google Security Research
    Published:27 Dec 2017
    9.8
    Critical

    CVE-2015-7874

    Last Modified: 2 Jan 2016

    Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname.

    Source:Guillaume Kaddouch
    Published:15 Jan 2020
    7.7
    High

    CVE-2015-7865

    Last Modified: 23 Nov 2015

    nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows does not properly restrict access to the stereosvrpipe named pipe, which allows local users to gain privileges via a commandline in a number 2 command, which is stored in the HKEY_LOCAL_MACHINE explorer Run registry key, a different vulnerability than CVE-2011-4784.

    Source:Google Security Research
    Published:24 Nov 2015
    7.5
    High

    CVE-2015-7858

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7297.

    Source:Metasploit
    Published:29 Oct 2015
    7.5
    High

    CVE-2015-7857

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.php in Joomla! 3.2 before 3.4.5 allows remote attackers to execute arbitrary SQL commands via the list[select] parameter to index.php.

    Source:Metasploit
    Published:29 Oct 2015
    6.5
    Medium

    CVE-2015-7855

    Last Modified: 28 Nov 2016

    The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value.

    Source:Magnus Klaaborg Stubman
    Published:21 Oct 2015
    7.5
    High

    CVE-2015-7808

    Last Modified: 21 Aug 2020

    The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.

    Source:Metasploit
    Published:24 Nov 2015
    9.3
    Critical

    CVE-2015-7805

    Last Modified: 13 Oct 2015

    Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file.

    Source:Marco Romano
    Published:12 Oct 2015
    7.5
    High

    CVE-2015-7768

    Last Modified: 21 Sept 2015

    Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD command.

    Source:Metasploit
    Published:9 Oct 2015
    7.5
    High

    CVE-2015-7767

    Last Modified: 22 Aug 2015

    Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long USER command.

    Source:Shankar Damodaran
    Published:9 Oct 2015
    9
    Critical

    CVE-2015-7766

    Last Modified: 17 Sept 2015

    PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by "INSERT/**/INTO."

    Source:Metasploit
    Published:9 Oct 2015
    9
    Critical

    CVE-2015-7765

    Last Modified: 17 Sept 2015

    ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.

    Source:Metasploit
    Published:9 Oct 2015
    9.8
    Critical

    CVE-2015-7755

    Last Modified: 21 Apr 2026

    Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.

    Published:19 Dec 2015
    8.8
    High

    CVE-2015-7715

    Last Modified: 20 Dec 2016

    Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to administrator/index.php.

    Source:Bikramaditya Guha
    Published:18 Oct 2017
    7.2
    High

    CVE-2015-7714

    Last Modified: 20 Dec 2016

    Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action, (3) pshow in an update_field action, (4) css, (5) tip, (6) cat_id, (7) text_search, (8) plisting, or (9) pwizard parameter to administrator/index.php.

    Source:Bikramaditya Guha
    Published:18 Oct 2017
    10
    Critical

    CVE-2015-7709

    Last Modified: 1 Apr 2017

    The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.

    Source:Metasploit
    Published:5 Oct 2015
    6.5
    Medium

    CVE-2015-7707

    Last Modified: 15 Sept 2015

    Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.

    Source:hyp3rlinx
    Published:5 Oct 2015