|
268991
|
7.8 |
HIGH
Local
|
redhat debian canonical spice_project
|
enterprise_linux_server_eus enterprise_linux_hpc_node enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux ubuntu_linux spice enterprise_…
|
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host v…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5260
|
2024-11-21 11:32 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268992
|
5.5 |
MEDIUM
Local
|
criu opensuse
|
checkpoint\/restore_in_userspace opensuse
|
The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access.
|
CWE-200
Information Exposure
|
CVE-2015-5231
|
2024-11-21 11:32 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268993
|
7.8 |
HIGH
Local
|
opensuse criu
|
opensuse checkpoint\/restore_in_userspace
|
The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing files via unspecified vectors related to a director…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5228
|
2024-11-21 11:32 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268994
|
9.1 |
CRITICAL
Network
|
ibm suse redhat
|
java_sdk linux_enterprise_server linux_enterprise_software_development_kit suse_linux_enterprise_server websphere_application_server satellite
|
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject …
|
CWE-200
Information Exposure
|
CVE-2015-5041
|
2024-11-21 11:32 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268995
|
4.4 |
MEDIUM
Local
|
apache
|
cordova
|
Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link.
|
CWE-20
Improper Input Validation
|
CVE-2015-5208
|
2024-11-21 11:32 |
2016-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268996
|
5.3 |
MEDIUM
Local
|
apache
|
cordova
|
Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.
|
CWE-254 CWE-284
7PK - Security Features Improper Access Control
|
CVE-2015-5207
|
2024-11-21 11:32 |
2016-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268997
|
5.9 |
MEDIUM
Network
|
samba canonical
|
samba ubuntu_linux
|
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a…
|
NVD-CWE-noinfo
|
CVE-2015-5370
|
2024-11-21 11:32 |
2016-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268998
|
7.5 |
HIGH
Network
|
redhat openstack
|
openstack tripleo_heat_templates
|
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline w…
|
CWE-200
Information Exposure
|
CVE-2015-5271
|
2024-11-21 11:32 |
2016-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268999
|
8.1 |
HIGH
Network
|
apache
|
camel
|
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arb…
|
CWE-19
Data Processing Errors
|
CVE-2015-5348
|
2024-11-21 11:32 |
2016-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269000
|
6.5 |
MEDIUM
Network
|
redhat canonical
|
libvirt ubuntu_linux
|
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unl…
|
CWE-284
Improper Access Control
|
CVE-2015-5247
|
2024-11-21 11:32 |
2016-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|