|
269451
|
6.1 |
MEDIUM
Network
|
ibm
|
websphere_portal
|
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF19, and 8.5.0 before CF08 a…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4993
|
2024-11-21 11:32 |
2015-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269452
|
- |
|
redhat gnu canonical
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node glibc ubuntu_linux
|
The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corrup…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5277
|
2024-11-21 11:32 |
2015-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269453
|
- |
|
apache
|
cordova_file_transfer
|
CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before 1.3.0 allows remote attackers to inject arbitrary headers via CRLF sequences …
|
NVD-CWE-Other
|
CVE-2015-5204
|
2024-11-21 11:32 |
2015-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269454
|
- |
|
redhat
|
jboss_enterprise_application_platform
|
Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the server, which allows remote authenticated users with the Monitor, Deployer, or Aud…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5304
|
2024-11-21 11:32 |
2015-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269455
|
- |
|
canonical redhat apple xmlsoft hp debian
|
ubuntu_linux enterprise_linux_hpc_node enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation watchos iphone_os mac_os_x tvos libxml2 icewall_file…
|
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU cons…
|
CWE-399
Resource Management Errors
|
CVE-2015-5312
|
2024-11-21 11:32 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269456
|
- |
|
ibm
|
websphere_application_server
|
The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 does not properly encrypt data, which allows remote authenticated users to obtain…
|
CWE-200
Information Exposure
|
CVE-2015-5004
|
2024-11-21 11:32 |
2015-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269457
|
- |
|
opensuse simon_tatham
|
leap opensuse putty
|
Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via an ECH (erase characters…
|
CWE-189
Numeric Errors
|
CVE-2015-5309
|
2024-11-21 11:32 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269458
|
- |
|
ibm redhat suse
|
java_2_sdk java_sdk enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation satellite enterprise_linux_server_eus linux_enterprise_server linux_enterpris…
|
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attacke…
|
CWE-200
Information Exposure
|
CVE-2015-5006
|
2024-11-21 11:32 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269459
|
- |
|
redhat
|
libreport
|
libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1)…
|
CWE-200
Information Exposure
|
CVE-2015-5302
|
2024-11-21 11:32 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269460
|
- |
|
redhat
|
automatic_bug_reporting_tool enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable na…
|
CWE-59
Link Following
|
CVE-2015-5287
|
2024-11-21 11:32 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|