|
270651
|
5.9 |
MEDIUM
Network
|
oracle mariadb fedoraproject debian redhat php
|
mysql mysql_connector\/c mariadb fedora debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_eus enterprise_linux_ser…
|
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle atta…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-3152
|
2024-11-21 11:28 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270652
|
7.5 |
HIGH
Network
|
libssh canonical debian fedoraproject
|
libssh ubuntu_linux debian_linux fedora
|
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (…
|
NVD-CWE-Other
|
CVE-2015-3146
|
2024-11-21 11:28 |
2016-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270653
|
5.9 |
MEDIUM
Network
|
erlang oracle opensuse
|
erlang\/otp solaris opensuse
|
Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle …
|
CWE-200
Information Exposure
|
CVE-2015-2774
|
2024-11-21 11:28 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270654
|
5.9 |
MEDIUM
Network
|
oracle openssl
|
tuxedo exalogic_infrastructure peoplesoft_enterprise_peopletools openssl oss_support_tools vm_virtualbox
|
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection…
|
CWE-310 CWE-200
Cryptographic Issues Information Exposure
|
CVE-2015-3197
|
2024-11-21 11:28 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270655
|
9.8 |
CRITICAL
Network
|
apache
|
cloudstack
|
Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.
|
CWE-255
Credentials Management
|
CVE-2015-3252
|
2024-11-21 11:28 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270656
|
4.9 |
MEDIUM
Network
|
apache
|
cloudstack
|
Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API ca…
|
CWE-200
Information Exposure
|
CVE-2015-3251
|
2024-11-21 11:28 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270657
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, which allows remote attackers to cause a denial of ser…
|
CWE-20
Improper Input Validation
|
CVE-2015-3182
|
2024-11-21 11:28 |
2016-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270658
|
6.1 |
MEDIUM
Network
|
orientdb
|
orientdb
|
The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct …
|
CWE-20
Improper Input Validation
|
CVE-2015-2918
|
2024-11-21 11:28 |
2015-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270659
|
5.9 |
MEDIUM
Network
|
orientdb
|
orientdb
|
server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class…
|
CWE-200
Information Exposure
|
CVE-2015-2913
|
2024-11-21 11:28 |
2015-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270660
|
8.8 |
HIGH
Network
|
orientdb
|
orientdb
|
The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values, which allows remote attackers to condu…
|
CWE-352
Origin Validation Error
|
CVE-2015-2912
|
2024-11-21 11:28 |
2015-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|