|
268921
|
7.5 |
HIGH
Network
|
blackcat-cms
|
blackcat_cms
|
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the dl parameter.
|
CWE-22
Path Traversal
|
CVE-2015-5079
|
2024-11-21 11:32 |
2018-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268922
|
5.9 |
MEDIUM
Network
|
w1.fi debian
|
wpa_supplicant debian_linux
|
The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a de…
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-5316
|
2024-11-21 11:32 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268923
|
5.9 |
MEDIUM
Network
|
w1.fi debian
|
wpa_supplicant debian_linux
|
The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when EAP-pwd is enabled in a ne…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5315
|
2024-11-21 11:32 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268924
|
5.9 |
MEDIUM
Network
|
w1.fi debian
|
wpa_supplicant debian_linux
|
The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used with (1) an interna…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5314
|
2024-11-21 11:32 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268925
|
8.8 |
HIGH
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cf-release
|
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails wit…
|
CWE-200
Information Exposure
|
CVE-2015-5173
|
2024-11-21 11:32 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268926
|
9.8 |
CRITICAL
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cf-release
|
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire …
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2015-5172
|
2024-11-21 11:32 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268927
|
9.8 |
CRITICAL
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cf-release
|
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified im…
|
CWE-613
Insufficient Session Expiration
|
CVE-2015-5171
|
2024-11-21 11:32 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268928
|
8.8 |
HIGH
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cf-release
|
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks…
|
CWE-352
Origin Validation Error
|
CVE-2015-5170
|
2024-11-21 11:32 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268929
|
5.4 |
MEDIUM
Network
|
axigen
|
axigen_mail_server
|
Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackers to inject arbitrary web script or HTML via an email atta…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5379
|
2024-11-21 11:32 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268930
|
7.5 |
HIGH
Network
|
openslp debian
|
openslp debian_linux
|
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
|
CWE-415
Double Free
|
CVE-2015-5177
|
2024-11-21 11:32 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|