OpenBravo Hibernate suffers from a remote HQL injection vulnerability. Vendor has patched this in versions 3.0PR15Q3.4 and 3.0PR15Q4.1.
Monthly Archives: January 2016
Dream Gallery 1.0 SQL Injection
Dream Gallery version 1.0 suffers from a remote SQL injection vulnerability.
Dolibarr 3.8.3 Cross Site Scripting
Dolibarr version 3.8.3 suffers from a stored cross site scripting vulnerability.
CVE-2015-6566
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.
CVE-2015-7706
Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to api/v3/public/shares/downloads/, the (2) authType parameter to api/v3/auth/login, or the (3) login parameter to api/v3/auth/reset_password.
CVE-2015-8230
Memory leak in Huawei eSpace 8950 IP phones with software before V200R003C00SPC300 allows remote attackers to cause a denial of service (memory consumption and restart) via a large number of crafted ARP packets.
CVE-2015-8231
Huawei eSpace 7910 and 7950 IP phones with software before V200R002C00SPC800 allow remote attackers with established sessions to cause a denial of service (device restart) via unspecified packets.
CVE-2015-8331 (vcn500)
The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 does not properly invalidate the session ID when an “abnormal exit” occurs, which allows remote attackers to conduct replay attacks via the session ID.
CVE-2015-8333
The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 allows remote authenticated users to change the IP address of the media server via crafted packets.
CVE-2015-8335 (vcn500)
Huawei VCN500 with software before V100R002C00SPC201 logs passwords in cleartext, which allows remote authenticated users to obtain sensitive information by triggering log generation and then reading the log.