|
269591
|
8.8 |
HIGH
Network
|
ibm
|
websphere_commerce
|
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 8 allows remote authenticated users to hijack the authenticat…
|
CWE-352
Origin Validation Error
|
CVE-2015-5007
|
2024-11-21 11:32 |
2016-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269592
|
8.6 |
HIGH
Network
|
apache
|
subversion
|
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which …
|
CWE-119 CWE-189
Incorrect Access of Indexable Resource ('Range Error') Numeric Errors
|
CVE-2015-5259
|
2024-11-21 11:32 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269593
|
9.8 |
CRITICAL
Network
|
redhat apache fedoraproject
|
openshift activemq fedora
|
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Ser…
|
CWE-20
Improper Input Validation
|
CVE-2015-5254
|
2024-11-21 11:32 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269594
|
4.3 |
MEDIUM
Adjacent
|
google
|
android
|
The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers …
|
CWE-200
Information Exposure
|
CVE-2015-5310
|
2024-11-21 11:32 |
2016-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269595
|
4.3 |
MEDIUM
Network
|
ibm
|
maximo_for_transportation maximo_for_utilities maximo_asset_management smartcloud_control_desk maximo_for_life_sciences maximo_asset_management_essentials maximo_for_nuclear_power
|
IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.2 IF1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.2 IF1 for SmartCloud Control Desk allow r…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5051
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269596
|
7.5 |
HIGH
Network
|
ibm
|
connections
|
IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 does not properly detect recursion during XML entity expansion, which allows remote attackers to cause a den…
|
NVD-CWE-Other
|
CVE-2015-5038
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269597
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site request forgery (CSRF) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to hijack the authentic…
|
CWE-352
Origin Validation Error
|
CVE-2015-5037
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269598
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5036
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269599
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5035
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269600
|
5.4 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
SQL injection vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2015-5023
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|