|
271121
|
7.8 |
HIGH
Local
|
redhat
|
automatic_bug_reporting_tool
|
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) does not properly handle the process environment before invoking abrt-action-install-debuginfo, whi…
|
NVD-CWE-noinfo
|
CVE-2015-3159
|
2024-11-21 11:28 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271122
|
7.8 |
HIGH
Local
|
redhat
|
automatic_bug_reporting_tool
|
Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files via unspecified vectors to the (1) N…
|
CWE-22
Path Traversal
|
CVE-2015-3151
|
2024-11-21 11:28 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271123
|
7.1 |
HIGH
Local
|
redhat
|
automatic_bug_reporting_tool
|
abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteEleme…
|
CWE-20
Improper Input Validation
|
CVE-2015-3150
|
2024-11-21 11:28 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271124
|
6.5 |
MEDIUM
Network
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server automatic_bug_reporting_tool enterprise_linux_server_eus enterprise_linux_server_tus enterprise_linux_s…
|
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other uns…
|
CWE-59
Link Following
|
CVE-2015-3147
|
2024-11-21 11:28 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271125
|
8.8 |
HIGH
Network
|
synametrics
|
synaman syncrify syntail
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567
|
CWE-352
Origin Validation Error
|
CVE-2015-3140
|
2024-11-21 11:28 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271126
|
6.1 |
MEDIUM
Network
|
ikiwiki fedoraproject
|
ikiwiki fedora
|
Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parame…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2793
|
2024-11-21 11:28 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271127
|
7.5 |
HIGH
Network
|
postgresql debian canonical
|
postgresql debian_linux ubuntu_linux
|
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which …
|
CWE-200
Information Exposure
|
CVE-2015-3167
|
2024-11-21 11:28 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271128
|
9.8 |
CRITICAL
Network
|
postgresql debian canonical
|
postgresql debian_linux ubuntu_linux
|
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3166
|
2024-11-21 11:28 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271129
|
6.1 |
MEDIUM
Network
|
projectpier
|
projectpier
|
Multiple cross-site scripting (XSS) vulnerabilities in Project-Pier ProjectPier-Core allow remote attackers to inject arbitrary web script or HTML via the search_for parameter to (1) search_by_tag.ph…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2796
|
2024-11-21 11:28 |
2018-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271130
|
5.9 |
MEDIUM
Network
|
yodobashi
|
yodobashi
|
The Yodobashi App for Android 1.2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-2981
|
2024-11-21 11:28 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|