|
269081
|
5.9 |
MEDIUM
Network
|
ana
|
all_nippon_airways
|
ANA App for Android 3.1.1 and earlier, and ANA App for iOS 3.3.6 and earlier does not verify SSL certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-5666
|
2024-11-21 11:33 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269082
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
|
CWE-601
Open Redirect
|
CVE-2015-5608
|
2024-11-21 11:33 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269083
|
8.8 |
HIGH
Network
|
ipython fedoraproject
|
ipython fedora
|
Cross-site request forgery in the REST API in IPython 2 and 3.
|
CWE-352
Origin Validation Error
|
CVE-2015-5607
|
2024-11-21 11:33 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269084
|
7.5 |
HIGH
Network
|
devscripts_devel_team fedoraproject
|
devscripts fedora
|
Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename.
|
CWE-59
Link Following
|
CVE-2015-5705
|
2024-11-21 11:33 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269085
|
6.5 |
MEDIUM
Network
|
openstack
|
designate
|
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-5695
|
2024-11-21 11:33 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269086
|
6.1 |
MEDIUM
Local
|
tug
|
texlive
|
mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE: this vulnerability exists due to the reversion of…
|
CWE-59
Link Following
|
CVE-2015-5701
|
2024-11-21 11:33 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269087
|
6.1 |
MEDIUM
Local
|
tug
|
texlive
|
mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.
|
CWE-59
Link Following
|
CVE-2015-5700
|
2024-11-21 11:33 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269088
|
5.9 |
MEDIUM
Network
|
elasticsearch elastic
|
logstash
|
Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to obt…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-5619
|
2024-11-21 11:33 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269089
|
6.1 |
MEDIUM
Network
|
zenphoto
|
zenphoto
|
The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site scripting (XSS) via a…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5594
|
2024-11-21 11:33 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269090
|
9.8 |
CRITICAL
Network
|
samsung
|
syncthru_6
|
Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary files via unspecified parameters to (1) upload/updateDriver or (2) upload/addD…
|
CWE-22
Path Traversal
|
CVE-2015-5473
|
2024-11-21 11:33 |
2017-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|