|
269131
|
8.8 |
HIGH
Network
|
django-cms
|
django_cms
|
Cross-site request forgery (CSRF) vulnerability in django CMS before 3.0.14, 3.1.x before 3.1.1 allows remote attackers to manipulate privileged users into performing unknown actions via unspecified …
|
CWE-352
Origin Validation Error
|
CVE-2015-5081
|
2024-11-21 11:32 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269132
|
6.1 |
MEDIUM
Network
|
broken_link_checker_project
|
broken_link_checker
|
Cross-site scripting (XSS) vulnerability exists in the Wordpress admin panel when the Broken Link Checker plugin before 1.10.9 is installed.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5057
|
2024-11-21 11:32 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269133
|
9.8 |
CRITICAL
Network
|
mod_nss_project
|
mod_nss
|
The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass application restrictions.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5244
|
2024-11-21 11:32 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269134
|
5.5 |
MEDIUM
Local
|
fedoraproject opensuse_project opensuse jasper_project
|
fedora leap opensuse jasper
|
Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
|
CWE-415
Double Free
|
CVE-2015-5203
|
2024-11-21 11:32 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269135
|
5.3 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
The "Project Documentation" feature in MantisBT 1.2.19 and earlier, when the threshold to access files ($g_view_proj_doc_threshold) is set to ANYBODY, allows remote authenticated users to download at…
|
CWE-200
Information Exposure
|
CVE-2015-5059
|
2024-11-21 11:32 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269136
|
6.7 |
MEDIUM
Local
|
vmware
|
tools
|
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privil…
|
CWE-362
Race Condition
|
CVE-2015-5191
|
2024-11-21 11:32 |
2017-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269137
|
5.5 |
MEDIUM
Local
|
fedoraproject opensuse_project opensuse jasper_project
|
fedora leap opensuse jasper
|
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) vi…
|
CWE-416
Use After Free
|
CVE-2015-5221
|
2024-11-21 11:32 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269138
|
6.5 |
MEDIUM
Network
|
candlepinproject
|
candlepin
|
Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.
|
CWE-200 CWE-399
Information Exposure Resource Management Errors
|
CVE-2015-5187
|
2024-11-21 11:32 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269139
|
7.5 |
HIGH
Network
|
fedoraproject suse opensuse redhat debian canonical ntp
|
fedora linux_enterprise_server manager_proxy linux_enterprise_debuginfo linux_enterprise_software_development_kit manager openstack_cloud linux_enterprise_desktop leap open…
|
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to…
|
CWE-361
7PK - Time and State
|
CVE-2015-5300
|
2024-11-21 11:32 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269140
|
7.5 |
HIGH
Network
|
fedoraproject suse redhat debian canonical ntp novell opensuse siemens oracle
|
fedora manager_proxy linux_enterprise_debuginfo manager linux_enterprise_server openstack_cloud enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infin…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2015-5219
|
2024-11-21 11:32 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|