Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2015-12-31 CVE-2015-5995 Permissions, Privileges, and Access Controls vulnerability in multiple products
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attackers to obtain administrative access via a certain admin substring in an HTTP Cookie header.
network
low complexity
tenda mediabridge CWE-264
critical
9.8
2015-12-31 CVE-2015-2874 Credentials Management vulnerability in multiple products
Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.
network
low complexity
seagate lacie CWE-255
critical
9.8
2015-12-30 CVE-2015-7792 Permissions, Privileges, and Access Controls vulnerability in Corega Cg-Wlbargs Firmware
Corega CG-WLBARGS devices allow remote attackers to perform administrative operations via unspecified vectors.
network
low complexity
corega CWE-264
critical
9.8
2015-12-30 CVE-2015-7251 Credentials Management vulnerability in ZTE Zxhn H108N R1A Firmware Zte.Bhs.Zxhnh108Nr1A.Hpe
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.
network
low complexity
zte CWE-255
critical
9.8
2015-12-28 CVE-2015-8459 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Adobe products
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8460, CVE-2015-8636, and CVE-2015-8645.
network
low complexity
adobe CWE-119
critical
10.0
2015-12-27 CVE-2015-6538 Unspecified vulnerability in Ephiphanyheathdata Cardio Server 3.3/4.0/4.1
The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL.
network
low complexity
ephiphanyheathdata
critical
9.8
2015-12-27 CVE-2015-6537 SQL Injection vulnerability in Epiphanyhealthdata Cardio Server 3.3
SQL injection vulnerability in the login page in Epiphany Cardio Server 3.3 allows remote attackers to execute arbitrary SQL commands via a crafted URL.
network
low complexity
epiphanyhealthdata CWE-89
critical
9.8
2015-12-24 CVE-2015-6792 Unspecified vulnerability in Google Chrome
The MIDI subsystem in Google Chrome before 47.0.2526.106 does not properly handle the sending of data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to midi_manager.cc, midi_manager_alsa.cc, and midi_manager_mac.cc, a different vulnerability than CVE-2015-8664.
network
low complexity
google
critical
9.8
2015-12-24 CVE-2015-7930 Unspecified vulnerability in Adcon A840 Telemetry Gateway Base Station Firmware
Adcon Telemetry A840 Telemetry Gateway Base Station has hardcoded credentials, which allows remote attackers to obtain administrative access via unspecified vectors.
network
low complexity
adcon
critical
10.0
2015-12-24 CVE-2015-8267 Permissions, Privileges, and Access Controls vulnerability in Dovestones AD Self Password Reset 3.0.3.0
The PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll in Dovestones AD Self Password Reset before 3.0.4.0 allows remote attackers to reset arbitrary passwords via a crafted request with a valid username.
network
low complexity
dovestones CWE-264
critical
10.0