|
266851
|
4.3 |
MEDIUM
Network
|
cybozu
|
office
|
Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.
|
CWE-200
Information Exposure
|
CVE-2015-8487
|
2024-11-21 11:38 |
2016-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266852
|
5.4 |
MEDIUM
Network
|
cybozu
|
office
|
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary report titles via unspecified vectors, a different vulnerability than CV…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8486
|
2024-11-21 11:38 |
2016-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266853
|
5.4 |
MEDIUM
Network
|
cybozu
|
office
|
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary posting titles via unspecified vectors, a different vulnerability than C…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8485
|
2024-11-21 11:38 |
2016-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266854
|
5.4 |
MEDIUM
Network
|
cybozu
|
office
|
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended calendar-viewing restrictions via unspecified vectors, a different vulnerability than CVE-2015-8485, CVE-2015-8…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-8484
|
2024-11-21 11:38 |
2016-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266855
|
7.4 |
HIGH
Network
|
cybozu
|
office
|
Open redirect vulnerability in Cybozu Office 10.2.0 through 10.3.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
|
NVD-CWE-Other
|
CVE-2015-8483
|
2024-11-21 11:38 |
2016-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266856
|
6.1 |
MEDIUM
Network
|
ibm
|
security_access_manager_for_web_8.0_firmware security_access_manager_9.0_firmware
|
Cross-site scripting (XSS) vulnerability in IBM Security Access Manager for Web 8.0 before 8.0.1.3 IF4 and 9.0 before 9.0.0.1 IF1 allows remote attackers to inject arbitrary web script or HTML via a …
|
CWE-79
Cross-site Scripting
|
CVE-2015-8531
|
2024-11-21 11:38 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266857
|
6.5 |
MEDIUM
Network
|
mit opensuse debian redhat oracle
|
kerberos_5 leap opensuse debian_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server …
|
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (mem…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2015-8631
|
2024-11-21 11:38 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266858
|
7.5 |
HIGH
Network
|
mit
|
kerberos_5
|
The (1) kadm5_create_principal_3 and (2) kadm5_modify_principal functions in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.4 and 1.14.x before 1.…
|
NVD-CWE-Other
|
CVE-2015-8630
|
2024-11-21 11:38 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266859
|
5.3 |
MEDIUM
Network
|
mit oracle debian opensuse redhat
|
kerberos_5 solaris linux debian_linux leap opensuse enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterpr…
|
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which…
|
CWE-125
Out-of-bounds Read
|
CVE-2015-8629
|
2024-11-21 11:38 |
2016-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266860
|
9.1 |
CRITICAL
Network
|
atlassian
|
bamboo
|
Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, …
|
CWE-284
Improper Access Control
|
CVE-2015-8361
|
2024-11-21 11:38 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|