|
271391
|
- |
|
zenphoto
|
zenphoto
|
Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2949
|
2024-11-21 11:28 |
2015-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271392
|
- |
|
zenphoto
|
zenphoto
|
Cross-site scripting (XSS) vulnerability in the image processor in Zenphoto before 1.4.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2948
|
2024-11-21 11:28 |
2015-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271393
|
- |
|
blue_coat
|
ssl_visibility_appliance_sv800_firmware ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv3800_firmware ssl_visibility_appliance_sv2800_firmware
|
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not set the secure flag for the administrator's cookie in an https se…
|
CWE-200
Information Exposure
|
CVE-2015-2855
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271394
|
- |
|
blue_coat
|
ssl_visibility_appliance_sv800_firmware ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv2800_firmware ssl_visibility_appliance_sv3800_firmware
|
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not send a restrictive X-Frame-Options HTTP header, which allows remo…
|
CWE-20
Improper Input Validation
|
CVE-2015-2854
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271395
|
- |
|
blue_coat
|
ssl_visibility_appliance_sv3800_firmware ssl_visibility_appliance_sv2800_firmware ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv800_firmware
|
Session fixation vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers to hijack web se…
|
NVD-CWE-Other
|
CVE-2015-2853
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271396
|
- |
|
blue_coat
|
ssl_visibility_appliance_sv2800_firmware ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv3800_firmware ssl_visibility_appliance_sv800_firmware
|
Cross-site request forgery (CSRF) vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers…
|
CWE-352
Origin Validation Error
|
CVE-2015-2852
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271397
|
- |
|
synology
|
cloud_station
|
client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change the ownership of arbitrary files, and consequently obtain root access, by spec…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2851
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271398
|
- |
|
canonical debian apple postgresql
|
ubuntu_linux debian_linux mac_os_x_server postgresql
|
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash…
|
NVD-CWE-Other
|
CVE-2015-3165
|
2024-11-21 11:28 |
2015-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271399
|
- |
|
linux fedoraproject oracle redhat debian
|
linux_kernel fedora linux solaris enterprise_mrg debian_linux
|
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigu…
|
CWE-17
Code
|
CVE-2015-2922
|
2024-11-21 11:28 |
2015-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271400
|
- |
|
debian linux canonical
|
debian_linux linux_kernel ubuntu_linux
|
arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protectio…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2830
|
2024-11-21 11:28 |
2015-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|