|
273971
|
- |
|
symantec
|
endpoint_protection_manager
|
Directory traversal vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to read arbitrary files via a rel…
|
CWE-22
Path Traversal
|
CVE-2015-1490
|
2024-11-21 11:25 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273972
|
- |
|
symantec
|
endpoint_protection_manager
|
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to gain privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1489
|
2024-11-21 11:25 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273973
|
- |
|
symantec
|
endpoint_protection_manager
|
An unspecified action handler in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to read arbitrary files via unknown v…
|
CWE-200
Information Exposure
|
CVE-2015-1488
|
2024-11-21 11:25 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273974
|
- |
|
symantec
|
endpoint_protection_manager
|
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtain administrator pri…
|
CWE-20
Improper Input Validation
|
CVE-2015-1487
|
2024-11-21 11:25 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273975
|
- |
|
symantec
|
endpoint_protection_manager
|
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new…
|
CWE-287
Improper Authentication
|
CVE-2015-1486
|
2024-11-21 11:25 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273976
|
- |
|
google opensuse redhat debian
|
chrome opensuse enterprise_linux_server_supplementary_eus enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary deb…
|
Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2015-1289
|
2024-11-21 11:25 |
2015-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273977
|
- |
|
google debian redhat opensuse
|
chrome debian_linux enterprise_linux_server_supplementary_eus enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary
|
The Spellcheck API implementation in Google Chrome before 44.0.2403.89 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorre…
|
CWE-17
Code
|
CVE-2015-1288
|
2024-11-21 11:25 |
2015-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273978
|
- |
|
opensuse google redhat debian
|
opensuse chrome enterprise_linux_server_supplementary_eus enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary deb…
|
Blink, as used in Google Chrome before 44.0.2403.89, enables a quirks-mode exception that limits the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content ty…
|
CWE-17
Code
|
CVE-2015-1287
|
2024-11-21 11:25 |
2015-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273979
|
- |
|
debian opensuse redhat google
|
debian_linux opensuse enterprise_linux_server_supplementary_eus enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary<…
|
Cross-site scripting (XSS) vulnerability in the V8ContextNativeHandler::GetModuleSystem function in extensions/renderer/v8_context_native_handler.cc in Google Chrome before 44.0.2403.89 allows remote…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1286
|
2024-11-21 11:25 |
2015-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273980
|
- |
|
redhat debian opensuse google
|
enterprise_linux_server_supplementary_eus enterprise_linux_desktop_supplementary enterprise_linux_server_supplementary enterprise_linux_workstation_supplementary debian_linux opensuse<…
|
The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, does not properly choose a truncation point, which …
|
CWE-200
Information Exposure
|
CVE-2015-1285
|
2024-11-21 11:25 |
2015-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|