Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-4607 | 1 Frontend User Upload Project | 1 Frontend User Upload | 2016-12-07 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in the Frontend User Upload (feupload) extension 0.5.0 and earlier for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension using a frontend form, then accessing it via a direct request to the file in the fileadmin folder. | |||||
CVE-2015-4608 | 1 Be User Log Project | 1 Be User Log | 2016-12-07 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in the BE User Log (beko_beuserlog) extension 1.1.1 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2015-4609 | 1 Wt Directory Project | 1 Wt Directory | 2016-12-07 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the wt_directory extension before 1.4.2 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-4610 | 1 Store Locator Project | 1 Store Locator | 2016-12-07 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the Store Locator (locator) extension before 3.3.1 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-4611 | 1 Smoelenboek Project | 1 Smoelenboek | 2016-12-07 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the Smoelenboek (ncgov_smoelenboek) extension before 1.0.9 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-4612 | 1 Faq-frequenty Asked Questions Project | 1 Faq-frequently Asked Questions | 2016-12-07 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the "FAQ - Frequently Asked Questions" (js_faq) extension before 1.2.1 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-4613 | 1 Developer Log Project | 1 Developer Log | 2016-12-07 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the backend module in the Developer Log (devlog) extension before 2.11.4 for TYPO3 allows remote editors to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2015-4628 | 1 Limesurvey | 1 Limesurvey | 2016-12-07 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands via the sid parameter. | |||||
CVE-2015-4640 | 2 Samsung, Swiftkey | 5 Galaxy S4, Galaxy S4 Mini, Galaxy S5 and 2 more | 2016-12-07 | 2.9 LOW | N/A |
The SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices relies on an HTTP connection to the skslm.swiftkey.net server, which allows man-in-the-middle attackers to write to language-pack files by modifying an HTTP response. NOTE: CVE-2015-4640 exploitation can be combined with CVE-2015-4641 exploitation for man-in-the-middle code execution. | |||||
CVE-2015-4641 | 2 Samsung, Swiftkey | 5 Galaxy S4, Galaxy S4 Mini, Galaxy S5 and 2 more | 2016-12-07 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in the SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices allows remote web servers to write to arbitrary files, and consequently execute arbitrary code in a privileged context, by leveraging control of the skslm.swiftkey.net domain name and providing a .. (dot dot) in an entry in a ZIP archive, as demonstrated by a traversal to the /data/dalvik-cache directory. | |||||
CVE-2015-4647 | 1 Panasonic | 1 Security Api Activex Sdk | 2016-12-07 | 6.8 MEDIUM | N/A |
Multiple stack-based buffer overflows in Ipropsapi in Panasonic Security API (PS-API) ActiveX SDK before 8.10.18 allow remote attackers to execute arbitrary code via a long string in the (1) FilePassword property or to the (2) GetStringInfo method. | |||||
CVE-2015-4648 | 1 Panasonic | 1 Security Api Activex Sdk | 2016-12-07 | 7.5 HIGH | N/A |
Stack-based buffer overflow in the Ipropsapi.ipropsapiCtrl.1 ActiveX control in ipropsapivideo in Panasonic Security API (PS-API) ActiveX SDK before 8.10.18 allows remote attackers to execute arbitrary code via a long string to the MulticastAddr method. | |||||
CVE-2015-4654 | 1 Joomla | 1 Joomla\! | 2016-12-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in the EQ Event Calendar component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to eqfullevent. | |||||
CVE-2015-4659 | 1 Labsmedia | 1 Clickheat | 2016-12-07 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php. | |||||
CVE-2015-4671 | 1 Opencart | 1 Opencart | 2016-12-07 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the zone_id parameter to index.php. | |||||
CVE-2015-4675 | 1 Tinysrp Project | 1 Tinysrp | 2016-12-07 | 7.5 HIGH | N/A |
Buffer overflow in the Tiny SRP library (aka TinySRP) allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted size value for the username field. | |||||
CVE-2015-4676 | 1 Aftab | 1 Tickfa | 2016-12-07 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in ticket.php in TickFa 1.x allows remote authenticated users to execute arbitrary SQL commands via the tid parameter in a read action. | |||||
CVE-2015-4677 | 1 Fiverrscript | 1 Fiverrscript | 2016-12-07 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in FiverrScript (aka Fiverr Script) 7.2 allows remote attackers to hijack the authentication of administrators for requests that create a new admin via a request to administrator/admins_create.php. | |||||
CVE-2015-4678 | 1 Persian Car Cms Project | 1 Persian Car Cms | 2016-12-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in Persian Car CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to the default URI. | |||||
CVE-2015-4679 | 1 Airties | 2 Rt-210, Rt-210 Firmware | 2016-12-07 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Airties RT-210 allow remote attackers to inject arbitrary web script or HTML via the (1) ddns_domainame or (2) ddns_account parameter to ddns.stm. |