|
270731
|
7.8 |
HIGH
Local
|
fortinet
|
fortimanager_firmware
|
Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3617
|
2024-11-21 11:29 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270732
|
7.8 |
HIGH
Local
|
open-uri-cached_project
|
open-uri-cached
|
The open-uri-cached rubygem allows local users to execute arbitrary Ruby code by creating a directory under /tmp containing "openuri-" followed by a crafted UID, and putting Ruby code in said directo…
|
CWE-20
Improper Input Validation
|
CVE-2015-3649
|
2024-11-21 11:29 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270733
|
9.8 |
CRITICAL
Network
|
fortinet
|
fortimanager_firmware
|
SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands via unspecified parameters.
|
CWE-89
SQL Injection
|
CVE-2015-3616
|
2024-11-21 11:29 |
2017-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270734
|
5.4 |
MEDIUM
Network
|
fortinet
|
fortimanager_firmware
|
Cross-site scripting (XSS) vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involvin…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3615
|
2024-11-21 11:29 |
2017-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270735
|
7.5 |
HIGH
Network
|
fortinet
|
fortimanager_firmware
|
Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspecified vulnerability.
|
CWE-200
Information Exposure
|
CVE-2015-3614
|
2024-11-21 11:29 |
2017-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270736
|
7.5 |
HIGH
Network
|
mod_nss_project
|
mod_nss
|
The mod_nss module before 1.0.11 in Fedora allows remote attackers to obtain cipher lists due to incorrect parsing of multi-keyword cipherstring.
|
CWE-200
Information Exposure
|
CVE-2015-3277
|
2024-11-21 11:29 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270737
|
7.5 |
HIGH
Network
|
ntp debian suse opensuse_project opensuse fedoraproject redhat
|
ntp debian_linux suse_linux_enterprise_server suse_linux_enterprise_desktop fedora enterprise_linux_for_scientific_computing enterprise_linux_server_from_rhui_6 enterprise_linux_…
|
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is betwe…
|
CWE-331
Insufficient Entropy
|
CVE-2015-3405
|
2024-11-21 11:29 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270738
|
5.5 |
MEDIUM
Local
|
google
|
android
|
The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash).
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-3839
|
2024-11-21 11:29 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270739
|
5.9 |
MEDIUM
Network
|
citrix
|
netscaler_application_delivery_controller netscaler_gateway
|
The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x before 9.3 Build 68.5, 10.0 through Build 78.6, 10.…
|
CWE-200
Information Exposure
|
CVE-2015-3642
|
2024-11-21 11:29 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270740
|
9.8 |
CRITICAL
Network
|
nss_compat_ossl_project
|
nss_compat_ossl
|
The cipherstring parsing code in nss_compat_ossl while in multi-keyword mode does not match the expected set of ciphers for a given cipher combination, which allows attackers to have unspecified impa…
|
CWE-20
Improper Input Validation
|
CVE-2015-3278
|
2024-11-21 11:29 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|