CVE-2015-7921 (gp-pro_ex_ex-ed, gp-pro_ex_pfxexedls, gp-pro_ex_pfxexedv, gp-pro_ex_pfxexgrpls)

CVE-2015-7921 (gp-pro_ex_ex-ed, gp-pro_ex_pfxexedls, gp-pro_ex_pfxexedv, gp-pro_ex_pfxexgrpls)

The FTP server in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 has hardcoded credentials, which makes it easier for remote attackers to bypass authentication by leveraging knowledge of these credentials.

Source: CVE-2015-7921 (gp-pro_ex_ex-ed, gp-pro_ex_pfxexedls, gp-pro_ex_pfxexedv, gp-pro_ex_pfxexgrpls)

CVE-2015-7921

CVE-2015-7921

The FTP server in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 has hardcoded credentials, which makes it easier for remote attackers to bypass authentication by leveraging knowledge of these credentials.

Source: CVE-2015-7921

CVE-2015-6313 (telepresence_server_software)

CVE-2015-6313 (telepresence_server_software)

Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Multiparty Media 310, 320, and 820; and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted HTTP requests that are not followed by an unspecified negotiation, aka Bug ID CSCuv47565.

Source: CVE-2015-6313 (telepresence_server_software)

CVE-2015-6313

CVE-2015-6313

Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Multiparty Media 310, 320, and 820; and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted HTTP requests that are not followed by an unspecified negotiation, aka Bug ID CSCuv47565.

Source: CVE-2015-6313

CVE-2016-3968 (cyberoam_cr100ing_utm_firmware, cyberoam_cr35ing_utm_firmware)

CVE-2016-3968 (cyberoam_cr100ing_utm_firmware, cyberoam_cr35ing_utm_firmware)

Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM appliance with firmware 10.6.2 MR-1 build 383, and CR35iNG UTM appliance with firmware 10.6.2 Build 378 allow remote attackers to inject arbitrary web script or HTML via the (1) ipFamily parameter to corporate/webpages/trafficdiscovery/LiveConnections.jsp; the (2) ipFamily, (3) applicationname, or (4) username parameter to corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp; or the (5) X-Forwarded-For HTTP header.

Source: CVE-2016-3968 (cyberoam_cr100ing_utm_firmware, cyberoam_cr35ing_utm_firmware)

CVE-2016-3968

CVE-2016-3968

Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM appliance with firmware 10.6.2 MR-1 build 383, and CR35iNG UTM appliance with firmware 10.6.2 Build 378 allow remote attackers to inject arbitrary web script or HTML via the (1) ipFamily parameter to corporate/webpages/trafficdiscovery/LiveConnections.jsp; the (2) ipFamily, (3) applicationname, or (4) username parameter to corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp; or the (5) X-Forwarded-For HTTP header.

Source: CVE-2016-3968