|
271131
|
9.8 |
CRITICAL
Network
|
apache
|
traffic_server
|
The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3249
|
2024-11-21 11:28 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271132
|
8.8 |
HIGH
Network
|
watchguard
|
hawkeye_g
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary acco…
|
CWE-352
Origin Validation Error
|
CVE-2015-2878
|
2024-11-21 11:28 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271133
|
5.9 |
MEDIUM
Network
|
fedoraproject
|
spin-kickstarts
|
fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora Atomic updates.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3229
|
2024-11-21 11:28 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271134
|
9.8 |
CRITICAL
Network
|
berta
|
berta_cms
|
Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct re…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-2780
|
2024-11-21 11:28 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271135
|
7.4 |
HIGH
Network
|
rakutencard
|
rakuten_card
|
Rakuten card App for iOS 5.2.0 through 5.2.4 does not verify SSL certificates which might allow remote attackers to execute man-in-the-middle attacks.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-2988
|
2024-11-21 11:28 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271136
|
7.5 |
HIGH
Network
|
accellion
|
file_transfer_appliance
|
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote attackers to read arbitrary files via a .. (d…
|
CWE-22
Path Traversal
|
CVE-2015-2856
|
2024-11-21 11:28 |
2017-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271137
|
7.5 |
HIGH
Network
|
tcpdump opensuse_project opensuse
|
tcpdump leap
|
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
|
CWE-20
Improper Input Validation
|
CVE-2015-3138
|
2024-11-21 11:28 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271138
|
4.7 |
MEDIUM
Local
|
openhpi
|
openhpi
|
openhpi/Makefile.am in OpenHPI before 3.6.0 uses world-writable permissions for /var/lib/openhpi directory, which allows local users, when quotas are not properly setup, to fill the filesystem hostin…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-3248
|
2024-11-21 11:28 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271139
|
6.5 |
MEDIUM
Network
|
uronode nodejs debian
|
uro_node node.js debian_linux
|
node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).
|
CWE-399
Resource Management Errors
|
CVE-2015-2927
|
2024-11-21 11:28 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271140
|
5.3 |
MEDIUM
Network
|
simple_ads_manager_project
|
simple_ads_manager
|
WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2015-2826
|
2024-11-21 11:28 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|