|
271571
|
6.1 |
MEDIUM
Network
|
drupal debian
|
drupal debian_linux
|
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks vi…
|
CWE-601
Open Redirect
|
CVE-2015-2750
|
2024-11-21 11:27 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271572
|
6.1 |
MEDIUM
Network
|
drupal debian
|
drupal debian_linux
|
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination pa…
|
CWE-601
Open Redirect
|
CVE-2015-2749
|
2024-11-21 11:27 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271573
|
7.8 |
HIGH
Local
|
epicor
|
crs_retail_store
|
The help window in Epicor CRS Retail Store before 3.2.03.01.008 allows local users to execute arbitrary code by injecting Javascript into the window source to create a button that spawns a command sh…
|
CWE-77
Command Injection
|
CVE-2015-2210
|
2024-11-21 11:27 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271574
|
7.5 |
HIGH
Network
|
gnome
|
librest
|
The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (appli…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2675
|
2024-11-21 11:27 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271575
|
4.7 |
MEDIUM
Local
|
openstack
|
compute
|
OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.
|
CWE-284
Improper Access Control
|
CVE-2015-2687
|
2024-11-21 11:27 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271576
|
5.9 |
MEDIUM
Network
|
restkit
|
restkit
|
Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Python with the default CERT_NONE value for the cert_reqs argument.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-2674
|
2024-11-21 11:27 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271577
|
7.5 |
HIGH
Network
|
capnproto
|
capnproto
|
Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an object reader, allows remote peers to cause a denial of service (CPU consumption)…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-2313
|
2024-11-21 11:27 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271578
|
7.5 |
HIGH
Network
|
capnproto
|
capnproto
|
Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and possibly general resource consumption) via a list with a large number of elemen…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-2312
|
2024-11-21 11:27 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271579
|
9.8 |
CRITICAL
Network
|
capnproto
|
capnproto
|
Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or possibly obtain sensitive information from memory or execut…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2015-2311
|
2024-11-21 11:27 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271580
|
9.1 |
CRITICAL
Network
|
capnproto
|
capnproto
|
Integer overflow in layout.c++ in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service or possibly obtain sensitive information from memory v…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2015-2310
|
2024-11-21 11:27 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|