Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-28 CVE-2016-0634 OS Command Injection vulnerability in GNU Bash 4.3
The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.
network
high complexity
gnu CWE-78
7.5
2017-08-28 CVE-2015-1876 Path Traversal vulnerability in Estrongs ES File Explorer 3.2.4.1
Directory traversal vulnerability in ES File Explorer 3.2.4.1.
network
low complexity
estrongs CWE-22
7.5
2017-08-28 CVE-2015-1445 HTTP Response Splitting vulnerability in Fli4L 3.10.0/4.0
HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.
network
low complexity
fli4l CWE-113
7.2
2017-08-28 CVE-2015-1443 Improper Input Validation vulnerability in Fli4L 3.10.0/4.0
The httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allows remote attackers to execute arbitrary code.
network
low complexity
fli4l CWE-20
8.8
2017-08-28 CVE-2015-1386 Path Traversal vulnerability in Unshield Project Unshield 1.01
Directory traversal vulnerability in unshield 1.0-1.
network
low complexity
unshield-project CWE-22
7.5
2017-08-28 CVE-2015-1199 Path Traversal vulnerability in Ppmd Project Ppmd 10.15
Directory traversal vulnerability in ppmd 10.1-5.
network
low complexity
ppmd-project CWE-22
7.5
2017-08-28 CVE-2015-1198 Path Traversal vulnerability in Linux-Ha HA 0.999P+Dfsg5
Multiple directory traversal vulnerabilities in ha 0.999p+dfsg-5.
network
low complexity
linux-ha CWE-22
7.5
2017-08-28 CVE-2015-0974 Untrusted Search Path vulnerability in Mobilis Mobiconnect 1.0.0B03
Untrusted search path vulnerability in ZTE Datacard MF19 0V1.0.0B04 allows local users to gain privilege by modifying the 'Ucell Internet' directory to reference a malicious mms_dll_r.dll or mediaplayerdll.dll.
local
low complexity
mobilis CWE-426
7.8
2017-08-28 CVE-2015-0928 NULL Pointer Dereference vulnerability in Oisf Libhtp 0.5.15
libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).
network
low complexity
oisf CWE-476
7.5
2017-08-28 CVE-2015-0114 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM I Access for Windows 5.4/6.1/7.1
Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1.
local
low complexity
ibm CWE-119
7.8