|
274431
|
7.5 |
HIGH
Network
|
etherpad
|
etherpad
|
node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper substring check when exporting a padID.
|
CWE-200
Information Exposure
|
CVE-2015-2298
|
2024-11-21 11:27 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274432
|
9.8 |
CRITICAL
Network
|
mono-project debian
|
mono debian_linux
|
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-2320
|
2024-11-21 11:27 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274433
|
7.5 |
HIGH
Network
|
mono-project
|
mono
|
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different v…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-2319
|
2024-11-21 11:27 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274434
|
8.1 |
HIGH
Network
|
mono-project debian
|
mono debian_linux
|
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-2318
|
2024-11-21 11:27 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274435
|
8.8 |
HIGH
Network
|
wpeasycart
|
wp_easycart
|
The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2673
|
2024-11-21 11:27 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274436
|
7.5 |
HIGH
Network
|
libcsoap_project
|
libcsoap
|
nanohttp in libcsoap allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Authorization header.
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-2297
|
2024-11-21 11:27 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274437
|
6.1 |
MEDIUM
Network
|
drupal debian
|
drupal debian_linux
|
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks vi…
|
CWE-601
Open Redirect
|
CVE-2015-2750
|
2024-11-21 11:27 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274438
|
6.1 |
MEDIUM
Network
|
drupal debian
|
drupal debian_linux
|
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination pa…
|
CWE-601
Open Redirect
|
CVE-2015-2749
|
2024-11-21 11:27 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274439
|
7.8 |
HIGH
Local
|
epicor
|
crs_retail_store
|
The help window in Epicor CRS Retail Store before 3.2.03.01.008 allows local users to execute arbitrary code by injecting Javascript into the window source to create a button that spawns a command sh…
|
CWE-77
Command Injection
|
CVE-2015-2210
|
2024-11-21 11:27 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274440
|
7.5 |
HIGH
Network
|
gnome
|
librest
|
The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (appli…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2675
|
2024-11-21 11:27 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|