|
270971
|
6.5 |
MEDIUM
Network
|
uronode nodejs debian
|
uro_node node.js debian_linux
|
node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).
|
CWE-399
Resource Management Errors
|
CVE-2015-2927
|
2024-11-21 11:28 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270972
|
5.3 |
MEDIUM
Network
|
simple_ads_manager_project
|
simple_ads_manager
|
WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2015-2826
|
2024-11-21 11:28 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270973
|
7.0 |
HIGH
Local
|
ossec
|
ossec
|
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3222
|
2024-11-21 11:28 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270974
|
6.1 |
MEDIUM
Network
|
askbot
|
askbot
|
Cross-site scripting (XSS) vulnerability in askbot 0.7.51-4.el6.noarch.
|
CWE-79
Cross-site Scripting
|
CVE-2015-3169
|
2024-11-21 11:28 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270975
|
7.5 |
HIGH
Network
|
apache
|
directory_ldap_api
|
Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-3250
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270976
|
4.3 |
MEDIUM
Network
|
redhat
|
beaker
|
The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote authenticated users to modify power types and key types via navigating to $BEA…
|
CWE-284
Improper Access Control
|
CVE-2015-3163
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270977
|
5.4 |
MEDIUM
Network
|
beaker-project
|
beaker
|
Cross-site scripting (XSS) vulnerability in the edit comment dialog in bkr/server/widgets.py in Beaker 20.1 allows remote authenticated users to inject arbitrary web script or HTML via writing a craf…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3162
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270978
|
4.8 |
MEDIUM
Network
|
beaker-project
|
beaker
|
The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals when producing JSON.
|
CWE-79
Cross-site Scripting
|
CVE-2015-3161
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270979
|
4.3 |
MEDIUM
Network
|
beaker-project
|
beaker
|
XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing e…
|
CWE-611
XXE
|
CVE-2015-3160
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270980
|
5.9 |
MEDIUM
Network
|
honda
|
moto_linc
|
Honda Moto LINC 1.6.1 does not verify SSL certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-2943
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|