9.3
    Critical

    CVE-2015-7652

    Last Modified: 17 Dec 2015

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 allows attackers to execute arbitrary code via a crafted gridFitType property value, a different vulnerability than CVE-2015-7651, CVE-2015-7653, CVE-2015-7654, CVE-2015-7655, CVE-2015-7656, CVE-2015-7657, CVE-2015-7658, CVE-2015-7660, CVE-2015-7661, CVE-2015-7663, CVE-2015-8042, CVE-2015-8043, CVE-2015-8044, and CVE-2015-8046.

    Source:Google Security Research
    Published:10 Nov 2015
    10
    Critical

    CVE-2015-7648

    Last Modified: 14 Dec 2015

    Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-7647.

    Source:Google Security Research
    Published:14 Oct 2015
    10
    Critical

    CVE-2015-7647

    Last Modified: 14 Dec 2015

    Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-7648.

    Source:Google Security Research
    Published:14 Oct 2015
    7.8
    High

    CVE-2015-7645

    Last Modified: 19 Oct 2017

    Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.

    Source:Google Security Research
    Published:14 Oct 2015
    10
    Critical

    CVE-2015-7622

    Last Modified: 27 Oct 2016

    Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6685, CVE-2015-6686, CVE-2015-6693, CVE-2015-6694, and CVE-2015-6695.

    Source:Francis Provencher
    Published:14 Oct 2015
    8.1
    High

    CVE-2015-7611

    Last Modified: 24 Feb 2020

    Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified vectors.

    Source:Metasploit
    Published:7 Jun 2016
    7.8
    High

    CVE-2015-7603

    Last Modified: 22 Sept 2015

    Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in a RETR command.

    Source:shinnai
    Published:29 Sept 2015
    7.8
    High

    CVE-2015-7602

    Last Modified: 28 Sept 2015

    Directory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in a RETR command.

    Source:Jay Turla
    Published:29 Sept 2015
    7.8
    High

    CVE-2015-7601

    Last Modified: 28 Sept 2015

    Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a RETR command.

    Source:Jay Turla
    Published:29 Sept 2015
    Low

    CVE-2015-7572

    Last Modified: 10 Feb 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0237. Reason: This candidate is a duplicate of CVE-2013-0237. Notes: All CVE users should reference CVE-2013-0237 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:SEC Consult
    Published:24 Apr 2017
    7.8
    High

    CVE-2015-7571

    Last Modified: 10 Feb 2016

    Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.

    Source:SEC Consult
    Published:7 Aug 2017
    7.2
    High

    CVE-2015-7570

    Last Modified: 10 Feb 2016

    Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports via the dbhost parameter to libs/org/adodb_lite/tests/test_adodb_lite.php, libs/org/adodb_lite/tests/test_datadictionary.php, or libs/org/adodb_lite/tests/test_adodb_lite_sessions.php.

    Source:SEC Consult
    Published:24 Apr 2017
    8.8
    High

    CVE-2015-7569

    Last Modified: 10 Feb 2016

    SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter.

    Source:SEC Consult
    Published:24 Apr 2017
    9.8
    Critical

    CVE-2015-7568

    Last Modified: 10 Feb 2016

    SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.

    Source:SEC Consult
    Published:24 Apr 2017
    9.8
    Critical

    CVE-2015-7567

    Last Modified: 10 Feb 2016

    SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token" parameter.

    Source:SEC Consult
    Published:18 Feb 2020
    4.6
    Medium

    CVE-2015-7566

    Last Modified: 9 Mar 2016

    The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a bulk-out endpoint.

    Source:OpenSource Security
    Published:11 Jan 2016
    9.8
    Critical

    CVE-2015-7564

    Last Modified: 14 Mar 2016

    Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b) errors_logs or (c) access_logs action to view.query.php.

    Source:Vincent Malguy
    Published:12 Apr 2017
    8.8
    High

    CVE-2015-7563

    Last Modified: 14 Mar 2016

    Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user.

    Source:Vincent Malguy
    Published:12 Apr 2017
    6.1
    Medium

    CVE-2015-7562

    Last Modified: 14 Mar 2016

    Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) label value of an item or (2) name of a role.

    Source:Vincent Malguy
    Published:12 Apr 2017
    7.8
    High

    CVE-2015-7556

    Last Modified: 30 Dec 2015

    DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program.

    Source:Larry W. Cashdollar
    Published:15 Jan 2020
    8.1
    High

    CVE-2015-7547

    Last Modified: 6 Dec 2016

    Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

    Source:Google Security Research
    Published:16 Feb 2016
    9.8
    Critical

    CVE-2015-7545

    Last Modified: 12 Apr 2025

    The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.

    Published:5 Oct 2015
    4.6
    Medium

    CVE-2015-7515

    Last Modified: 4 Sept 2016

    The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device that lacks endpoints.

    Source:OpenSource Security
    Published:25 Nov 2015
    9.8
    Critical

    CVE-2015-7501

    Last Modified: 20 Apr 2025

    Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

    Published:6 Nov 2015
    9.8
    Critical

    CVE-2015-7450

    Last Modified: 15 Mar 2017

    Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

    Source:Metasploit
    Published:2 Jan 2016
    5.5
    Medium

    CVE-2015-7422

    Last Modified: 18 Nov 2015

    Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via unspecified vectors.

    Source:hyp3rlinx
    Published:2 Jan 2016
    7.5
    High

    CVE-2015-7387

    Last Modified: 29 Sept 2015

    ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query parameter to event/runQuery.do, as demonstrated by "SELECT 1;INSERT INTO." Fixed in Build 11200.

    Source:xistence
    Published:28 Sept 2015
    7.5
    High

    CVE-2015-7382

    Last Modified: 23 Sept 2015

    SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary SQL commands via the defaultCharacterSet parameter, a different issue than CVE-2015-6009.

    Source:Mohab Ali
    Published:28 Sept 2015
    7.5
    High

    CVE-2015-7381

    Last Modified: 23 Sept 2015

    Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary PHP code via the (1) pathToMYSQL or (2) databaseStructureFile parameter, a different issue than CVE-2015-6008.

    Source:Mohab Ali
    Published:28 Sept 2015
    7.8
    High

    CVE-2015-7378

    Last Modified: 6 Apr 2016

    Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which allows local users to gain SYSTEM privileges by modifying Panda_URL_Filteringb.exe.

    Source:Kyriakos Economou
    Published:18 Apr 2016
    7.8
    High

    CVE-2015-7358

    Last Modified: 5 Oct 2015

    The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted volume over an existing drive letter and gain privileges via an entry in the /GLOBAL?? directory.

    Source:Google Security Research
    Published:2 Oct 2017
    4.8
    Medium

    CVE-2015-7347

    Last Modified: 10 Oct 2016

    Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1.

    Source:hyp3rlinx
    Published:20 Sept 2017
    9.8
    Critical

    CVE-2015-7346

    Last Modified: 10 Oct 2016

    SQL injection vulnerability in ZCMS 1.1.

    Source:hyp3rlinx
    Published:7 Jun 2017
    6.5
    Medium

    CVE-2015-7309

    Last Modified: 15 Sept 2015

    The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authenticated users to execute arbitrary code by renaming a crafted file and then directly accessing it.

    Source:Metasploit
    Published:22 Sept 2015
    7.5
    High

    CVE-2015-7297

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.

    Source:Metasploit
    Published:29 Oct 2015
    8.8
    High

    CVE-2015-7293

    Last Modified: 7 Oct 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.

    Source:hyp3rlinx
    Published:25 Sept 2017
    8.8
    High

    CVE-2015-7259

    Last Modified: 20 Nov 2015

    ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, which allows remote authenticated users to login to a target account via any of its username and password pairs.

    Source:Karn Ganeshen
    Published:24 Aug 2017
    8.8
    High

    CVE-2015-7258

    Last Modified: 20 Nov 2015

    ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.

    Source:Karn Ganeshen
    Published:24 Aug 2017
    7.5
    High

    CVE-2015-7257

    Last Modified: 20 Nov 2015

    ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".

    Source:Karn Ganeshen
    Published:24 Aug 2017
    5
    Medium

    CVE-2015-7254

    Last Modified: 14 Dec 2018

    Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI.

    Source:Rebellion
    Published:7 Nov 2015
    6.1
    Medium

    CVE-2015-7252

    Last Modified: 20 Nov 2015

    Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to inject arbitrary web script or HTML via the errorpage parameter.

    Source:Karn Ganeshen
    Published:30 Dec 2015
    9.8
    Critical

    CVE-2015-7251

    Last Modified: 20 Nov 2015

    ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.

    Source:Karn Ganeshen
    Published:30 Dec 2015
    7.5
    High

    CVE-2015-7250

    Last Modified: 20 Nov 2015

    Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.

    Source:Karn Ganeshen
    Published:30 Dec 2015
    4.9
    Medium

    CVE-2015-7249

    Last Modified: 20 Nov 2015

    ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access restrictions via a modified request, as demonstrated by leveraging the support account to change a password via a cgi-bin/webproc accountpsd action.

    Source:Karn Ganeshen
    Published:30 Dec 2015
    7.5
    High

    CVE-2015-7248

    Last Modified: 20 Nov 2015

    ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password hashes by reading the cgi-bin/webproc HTML source code, a different vulnerability than CVE-2015-8703.

    Source:Karn Ganeshen
    Published:30 Dec 2015
    9.8
    Critical

    CVE-2015-7247

    Last Modified: 4 Feb 2016

    D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration backup, which allows remote attackers to obtain sensitive information.

    Source:Karn Ganeshen
    Published:24 Apr 2017
    9.8
    Critical

    CVE-2015-7246

    Last Modified: 4 Feb 2016

    D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative access.

    Source:Karn Ganeshen
    Published:24 Apr 2017
    7.5
    High

    CVE-2015-7245

    Last Modified: 4 Feb 2016

    Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.

    Source:Karn Ganeshen
    Published:24 Apr 2017
    7.5
    High

    CVE-2015-7243

    Last Modified: 11 Jan 2017

    Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted WAV file.

    Source:Robbie Corley
    Published:18 Sept 2015
    9.8
    Critical

    CVE-2015-7241

    Last Modified: 22 Sept 2015

    XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.

    Source:Lukasz Miedzinski
    Published:6 Sept 2017