CVE-2015-0774
published 2015-06-12CVE-2015-0774: Cross-site scripting (XSS) vulnerability in Cisco Application and Content Networking System (ACNS) 5.5(9) allows remote attackers to inject arbitrary web…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.55%
72.1th percentile
Cross-site scripting (XSS) vulnerability in Cisco Application and Content Networking System (ACNS) 5.5(9) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuu70650.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | application_and_content_networking_system_software | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat7.2HIGH
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: pipe buffer state corruption after unsuccessful atomic read from pipe
vendor_redhat·2016-02-02·CVSS 7.2
CVE-2016-0774 [HIGH] kernel: pipe buffer state corruption after unsuccessful atomic read from pipe
kernel: pipe buffer state corruption after unsuccessful atomic read from pipe
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux package before 3.2.73-2+deb7u3 on Debian wheezy and the kernel package before 3.10.0-229.26.2 on Red Hat Enterprise Linux (RHEL) 7.1 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun." NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-1805.
It was found that the fix for CVE-2015-1805 incorrectly kept buffer offset and buffer length in sync on a failed atomic re
Cisco
Cisco Application and Content Networking System URL Page Return Cross-Site Scripting Vulnerability
vendor_cisco·2015-06-09·CVSS 4.3
CVE-2015-0774 [MEDIUM] CWE-79 Cisco Application and Content Networking System URL Page Return Cross-Site Scripting Vulnerability
Cisco Application and Content Networking System URL Page Return Cross-Site Scripting Vulnerability
A vulnerability in Cisco Application and Content Networking System (ACNS) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks.
The vulnerability is due to insufficient validation of the URL of pages that are not accessible to the end user that could be returned by an affected device. An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to follow a malicious link designed to deliver crafted JavaScript code. Processing the malicious link could allow the crafted JavaScript code to be executed in the user's browser when the error page is returned.
Cisco has confirmed the vulnerability; however, software updates are
GHSA
GHSA-3cvr-7qv6-j2f2: Cross-site scripting (XSS) vulnerability in Cisco Application and Content Networking System (ACNS) 5
ghsa_unreviewed·2022-05-17
CVE-2015-0774 [MEDIUM] CWE-79 GHSA-3cvr-7qv6-j2f2: Cross-site scripting (XSS) vulnerability in Cisco Application and Content Networking System (ACNS) 5
Cross-site scripting (XSS) vulnerability in Cisco Application and Content Networking System (ACNS) 5.5(9) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuu70650.
No detection rules found.
No public exploits indexed.
2015-06-12
Published