|
271141
|
7.0 |
HIGH
Local
|
ossec
|
ossec
|
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3222
|
2024-11-21 11:28 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271142
|
6.1 |
MEDIUM
Network
|
askbot
|
askbot
|
Cross-site scripting (XSS) vulnerability in askbot 0.7.51-4.el6.noarch.
|
CWE-79
Cross-site Scripting
|
CVE-2015-3169
|
2024-11-21 11:28 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271143
|
7.5 |
HIGH
Network
|
apache
|
directory_ldap_api
|
Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-3250
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271144
|
4.3 |
MEDIUM
Network
|
redhat
|
beaker
|
The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote authenticated users to modify power types and key types via navigating to $BEA…
|
CWE-284
Improper Access Control
|
CVE-2015-3163
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271145
|
5.4 |
MEDIUM
Network
|
beaker-project
|
beaker
|
Cross-site scripting (XSS) vulnerability in the edit comment dialog in bkr/server/widgets.py in Beaker 20.1 allows remote authenticated users to inject arbitrary web script or HTML via writing a craf…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3162
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271146
|
4.8 |
MEDIUM
Network
|
beaker-project
|
beaker
|
The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals when producing JSON.
|
CWE-79
Cross-site Scripting
|
CVE-2015-3161
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271147
|
4.3 |
MEDIUM
Network
|
beaker-project
|
beaker
|
XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing e…
|
CWE-611
XXE
|
CVE-2015-3160
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271148
|
5.9 |
MEDIUM
Network
|
honda
|
moto_linc
|
Honda Moto LINC 1.6.1 does not verify SSL certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-2943
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271149
|
5.5 |
MEDIUM
Local
|
php-fpm
|
php-fpm
|
php-fpm allows local users to write to or create arbitrary files via a symlink attack.
|
CWE-59
Link Following
|
CVE-2015-3211
|
2024-11-21 11:28 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271150
|
8.1 |
HIGH
Network
|
apple
|
pykerberos
|
The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other u…
|
CWE-287
Improper Authentication
|
CVE-2015-3206
|
2024-11-21 11:28 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|