|
273221
|
- |
|
eventsentry
|
eventsentry
|
Cross-site scripting (XSS) vulnerability in the Web Reports in EventSentry 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the pageId parameter to networktile/bullet.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1180
|
2024-11-21 11:24 |
2015-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273222
|
- |
|
osticket
|
osticket
|
Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1176
|
2024-11-21 11:24 |
2015-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273223
|
- |
|
canonical google chromium
|
ubuntu_linux chrome chromium
|
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2015-1205
|
2024-11-21 11:24 |
2015-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273224
|
- |
|
prestashop
|
prestashop
|
Cross-site scripting (XSS) vulnerability in blocklayered-ajax.php in the blocklayered module in PrestaShop 1.6.0.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the l…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1175
|
2024-11-21 11:24 |
2015-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273225
|
- |
|
ipass
|
ipass_open_mobile
|
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperly handled by a subp…
|
CWE-94
Code Injection
|
CVE-2015-0925
|
2024-11-21 11:24 |
2015-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273226
|
- |
|
opensuse oracle gnu
|
opensuse solaris patch
|
GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
|
CWE-59
Link Following
|
CVE-2015-1196
|
2024-11-21 11:24 |
2015-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273227
|
- |
|
openstack
|
image_registry_and_delivery_service_\(glance\)
|
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathna…
|
CWE-22
Path Traversal
|
CVE-2015-1195
|
2024-11-21 11:24 |
2015-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273228
|
- |
|
pax_project
|
pax
|
pax 1:20140703 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
|
CWE-59
Link Following
|
CVE-2015-1194
|
2024-11-21 11:24 |
2015-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273229
|
- |
|
pax_project
|
pax
|
Multiple directory traversal vulnerabilities in pax 1:20140703 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive.
|
CWE-22
Path Traversal
|
CVE-2015-1193
|
2024-11-21 11:24 |
2015-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273230
|
- |
|
kgb_project
|
kgb
|
Absolute path traversal vulnerability in kgb 1.0b4 allows remote attackers to write to arbitrary files via a full pathname in a crafted archive.
|
CWE-22
Path Traversal
|
CVE-2015-1192
|
2024-11-21 11:24 |
2015-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|