|
269641
|
- |
|
redhat
|
gluster_storage
|
OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a cra…
|
CWE-94
Code Injection
|
CVE-2015-5242
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269642
|
- |
|
redhat
|
enterprise_linux
|
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5281
|
2024-11-21 11:32 |
2015-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269643
|
- |
|
nvidia
|
gpu_driver
|
The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict acc…
|
CWE-284
Improper Access Control
|
CVE-2015-5053
|
2024-11-21 11:32 |
2015-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269644
|
- |
|
apache
|
cordova
|
Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended access…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5256
|
2024-11-21 11:32 |
2015-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269645
|
- |
|
hp adobe
|
xp7_command_view_advanced_edition xp_p9000_command_view_advanced_edition coldfusion livecycle_data_services
|
Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x be…
|
CWE-20
Improper Input Validation
|
CVE-2015-5255
|
2024-11-21 11:32 |
2015-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269646
|
- |
|
apache
|
cxf
|
The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid sig…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5253
|
2024-11-21 11:32 |
2015-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269647
|
- |
|
powerdns
|
authoritative
|
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
|
CWE-20
Improper Input Validation
|
CVE-2015-5311
|
2024-11-21 11:32 |
2015-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269648
|
- |
|
ipsilon_project
|
ipsilon
|
providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.2 and 1.1.x before 1.1.1 does not properly check permissions, which allows remote authenticated users to cau…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5301
|
2024-11-21 11:32 |
2015-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269649
|
- |
|
gnu
|
gcc
|
The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-dependent…
|
CWE-200
Information Exposure
|
CVE-2015-5276
|
2024-11-21 11:32 |
2015-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269650
|
- |
|
ipsilon_project
|
ipsilon
|
providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly check permissions to update the SAML2 Service Provider (SP) owner, which allows remote a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5217
|
2024-11-21 11:32 |
2015-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|