|
272031
|
7.5 |
HIGH
Network
|
jenkins
|
cloudbees
|
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.
|
CWE-611
XXE
|
CVE-2015-1809
|
2024-11-21 11:26 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272032
|
7.8 |
HIGH
Local
|
redhat
|
automatic_bug_reporting_tool
|
The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on a var_log_messages file.
|
CWE-59
Link Following
|
CVE-2015-1869
|
2024-11-21 11:26 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272033
|
6.5 |
MEDIUM
Network
|
tuxfamily
|
chrony
|
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (i…
|
NVD-CWE-Other
|
CVE-2015-1853
|
2024-11-21 11:26 |
2019-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272034
|
5.3 |
MEDIUM
Network
|
cabextract_project
|
cabextract
|
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character …
|
CWE-22
Path Traversal
|
CVE-2015-2060
|
2024-11-21 11:26 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272035
|
5.9 |
MEDIUM
Network
|
ruby-lang debian puppet
|
ruby trunk debian_linux puppet_enterprise puppet_agent
|
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attacker…
|
CWE-20
Improper Input Validation
|
CVE-2015-1855
|
2024-11-21 11:26 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272036
|
6.5 |
MEDIUM
Network
|
redhat
|
virtualization ovirt-engine
|
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
|
CWE-863
Incorrect Authorization
|
CVE-2015-1780
|
2024-11-21 11:26 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272037
|
5.3 |
MEDIUM
Network
|
linuxfoundation
|
opendaylight
|
The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions.
|
CWE-200
Information Exposure
|
CVE-2015-1857
|
2024-11-21 11:26 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272038
|
5.4 |
MEDIUM
Network
|
ibm
|
security_appscan
|
Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Fo…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1952
|
2024-11-21 11:26 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272039
|
5.9 |
MEDIUM
Network
|
redhat
|
rhn-client-tools
|
rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not properly validate hostnames in X.509 certificates from…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-1777
|
2024-11-21 11:26 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272040
|
5.3 |
MEDIUM
Network
|
ibm
|
websphere_mq
|
IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-middle attack, related to duplication of message data…
|
CWE-200
Information Exposure
|
CVE-2015-1957
|
2024-11-21 11:26 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|