CVE-2015-7262

CVSS v3 Score
7.5
High
CVSS v2 Score
8.5
High

Vulnerability Description

QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, allows remote authenticated users to gain privileges by registering an executable file, and then waiting for this file to be run in a privileged context after a reboot.

CVSS:9.8(Critical)

Linear eMerge E3-Series devices have a Version Control Failure.

CWE-182019
CVSS:3.7(Low)

NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communication with a source) ...

CWE-182016
CVSS:3.6(Low)

The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status...

CWE-182014
CVSS:4.3(Medium)

Barracuda Web Filter 7.x and 8.x before 8.1.0.005, when SSL Inspection is enabled, uses the same root Certification Authority certificate across different customers' installations, which makes it easi...

CWE-182015
CVSS:7.1(High)

lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and proc...

CWE-182015