|
269511
|
7.5 |
HIGH
Network
|
apache
|
cxf_fediz
|
Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2015-5175
|
2024-11-21 11:32 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269512
|
9.6 |
CRITICAL
Network
|
vmware debian
|
spring_framework debian_linux
|
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2015-5211
|
2024-11-21 11:32 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269513
|
7.5 |
HIGH
Network
|
teradata
|
teradata_express teradata_gateway
|
Teradata Gateway before 15.00.03.02-1 and 15.10.x before 15.10.00.01-1 and TD Express before 15.00.02.08_Sles10 and 15.00.02.08_Sles11 allow remote attackers to cause a denial of service (database cr…
|
CWE-20
Improper Input Validation
|
CVE-2015-5401
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269514
|
7.5 |
HIGH
Network
|
roundcube
|
roundcube_webmail webmail
|
Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.
|
CWE-200
Information Exposure
|
CVE-2015-5383
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269515
|
6.5 |
MEDIUM
Network
|
roundcube
|
roundcube_webmail webmail
|
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
|
CWE-200
Information Exposure
|
CVE-2015-5382
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269516
|
6.1 |
MEDIUM
Network
|
roundcube
|
roundcube_webmail webmail
|
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter t…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5381
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269517
|
6.1 |
MEDIUM
Network
|
apache
|
juddi
|
After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect the browser to an unintended web page in Apache j…
|
CWE-601
Open Redirect
|
CVE-2015-5241
|
2024-11-21 11:32 |
2017-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269518
|
5.5 |
MEDIUM
Local
|
ibm
|
security_access_manager_for_web_8.0_firmware security_access_manager_for_mobile security_access_manager_9.0_firmware
|
The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2015-5013
|
2024-11-21 11:32 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269519
|
9.1 |
CRITICAL
Network
|
ibm pcre
|
powerkvm pcre
|
Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from hea…
|
CWE-119 CWE-200
Incorrect Access of Indexable Resource ('Range Error') Information Exposure
|
CVE-2015-5073
|
2024-11-21 11:32 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269520
|
2.6 |
LOW
Adjacent
|
ibm
|
tealeaf_customer_experience
|
IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108 FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A b…
|
CWE-200
Information Exposure
|
CVE-2015-4961
|
2024-11-21 11:32 |
2016-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|