|
269151
|
6.5 |
MEDIUM
Network
|
roundcube
|
roundcube_webmail webmail
|
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
|
CWE-200
Information Exposure
|
CVE-2015-5382
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269152
|
6.1 |
MEDIUM
Network
|
roundcube
|
roundcube_webmail webmail
|
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter t…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5381
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269153
|
6.1 |
MEDIUM
Network
|
apache
|
juddi
|
After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect the browser to an unintended web page in Apache j…
|
CWE-601
Open Redirect
|
CVE-2015-5241
|
2024-11-21 11:32 |
2017-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269154
|
5.5 |
MEDIUM
Local
|
ibm
|
security_access_manager_for_web_8.0_firmware security_access_manager_for_mobile security_access_manager_9.0_firmware
|
The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2015-5013
|
2024-11-21 11:32 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269155
|
9.1 |
CRITICAL
Network
|
ibm pcre
|
powerkvm pcre
|
Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from hea…
|
CWE-119 CWE-200
Incorrect Access of Indexable Resource ('Range Error') Information Exposure
|
CVE-2015-5073
|
2024-11-21 11:32 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269156
|
2.6 |
LOW
Adjacent
|
ibm
|
tealeaf_customer_experience
|
IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108 FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A b…
|
CWE-200
Information Exposure
|
CVE-2015-4961
|
2024-11-21 11:32 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269157
|
7.5 |
HIGH
Network
|
openstack
|
nova glance cinder
|
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attack…
|
CWE-399
Resource Management Errors
|
CVE-2015-5162
|
2024-11-21 11:32 |
2016-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269158
|
5.4 |
MEDIUM
Network
|
phpvibe
|
phpvibe
|
Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5399
|
2024-11-21 11:32 |
2016-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269159
|
7.1 |
HIGH
Local
|
canonical redhat debian spice_project
|
ubuntu_linux enterprise_linux_server_eus enterprise_linux_hpc_node enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_hpc_node_eus deb…
|
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5261
|
2024-11-21 11:32 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269160
|
7.8 |
HIGH
Local
|
redhat debian canonical spice_project
|
enterprise_linux_server_eus enterprise_linux_hpc_node enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux ubuntu_linux spice enterprise_…
|
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host v…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5260
|
2024-11-21 11:32 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|