|
269161
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the usersp…
|
CWE-125
Out-of-bounds Read
|
CVE-2015-9289
|
2024-11-21 11:40 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269162
|
9.8 |
CRITICAL
Network
|
cam
|
the_university_of_cambridge_web_authentication_system_apache_authentication_agent
|
Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification field ("kid") of the IdP's HTTP response message ("WLS-Response") can be manipulate…
|
CWE-22
Path Traversal
|
CVE-2015-9287
|
2024-11-21 11:40 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269163
|
6.1 |
MEDIUM
Network
|
nodebb
|
nodebb
|
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9286
|
2024-11-21 11:40 |
2019-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269164
|
6.1 |
MEDIUM
Network
|
esotalk
|
esotalk
|
esoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9285
|
2024-11-21 11:40 |
2019-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269165
|
8.8 |
HIGH
Network
|
omniauth
|
omniauth
|
The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without …
|
CWE-352
Origin Validation Error
|
CVE-2015-9284
|
2024-11-21 11:40 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269166
|
6.1 |
MEDIUM
Network
|
grafana
|
piechart-panel
|
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an atta…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9282
|
2024-11-21 11:40 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269167
|
6.1 |
MEDIUM
Network
|
sas
|
web_infrastructure_platform
|
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9281
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269168
|
10.0 |
CRITICAL
Network
|
mailenable
|
mailenable
|
MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
|
CWE-611
XXE
|
CVE-2015-9280
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269169
|
6.1 |
MEDIUM
Network
|
mailenable
|
mailenable
|
MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9279
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269170
|
9.8 |
CRITICAL
Network
|
mailenable
|
mailenable
|
MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request.
|
CWE-255
Credentials Management
|
CVE-2015-9278
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|