|
270691
|
- |
|
thecartpress
|
thecartpress_ecommerce_shopping_cart
|
Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attacke…
|
CWE-352
Origin Validation Error
|
CVE-2015-3986
|
2024-11-21 11:30 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270692
|
- |
|
fedora
|
pacemaker_configuration_system
|
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via …
|
CWE-310
Cryptographic Issues
|
CVE-2015-3983
|
2024-11-21 11:30 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270693
|
- |
|
sap
|
netweaver_rfc_sdk
|
SAP NetWeaver RFC SDK allows attackers to obtain sensitive information via unspecified vectors, aka SAP Security Note 2084037.
|
CWE-200
Information Exposure
|
CVE-2015-3981
|
2024-11-21 11:30 |
2015-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270694
|
- |
|
sap
|
customer_relationship_management
|
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.
|
CWE-89
SQL Injection
|
CVE-2015-3980
|
2024-11-21 11:30 |
2015-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270695
|
- |
|
sap
|
customer_relationship_management
|
Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.
|
NVD-CWE-noinfo
|
CVE-2015-3979
|
2024-11-21 11:30 |
2015-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270696
|
- |
|
sap
|
sybase_unwired_platform_online_data_proxy
|
SAP Sybase Unwired Platform Online Data Proxy allows local users to obtain usernames and passwords via the DataVault, aka SAP Security Note 2094830.
|
CWE-200
Information Exposure
|
CVE-2015-3978
|
2024-11-21 11:30 |
2015-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270697
|
8.8 |
HIGH
Adjacent
|
yubico
|
ykneo-openpgp
|
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2015-3298
|
2024-11-21 11:29 |
2022-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270698
|
7.5 |
HIGH
Network
|
bitcoin
|
bitcoin_core
|
bitcoind and Bitcoin-Qt prior to 0.10.2 allow attackers to cause a denial of service (disabled functionality such as a client application crash) via an "Easy" attack.
|
NVD-CWE-noinfo
|
CVE-2015-3641
|
2024-11-21 11:29 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270699
|
7.5 |
HIGH
Network
|
etherpad
|
etherpad
|
Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permissions of the user running the service via a .. (do…
|
CWE-22
Path Traversal
|
CVE-2015-3309
|
2024-11-21 11:29 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270700
|
8.8 |
HIGH
Network
|
netcracker
|
resource_management_system
|
Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) ctrl, (2) h____%2427, (3) h__…
|
CWE-89
SQL Injection
|
CVE-2015-3423
|
2024-11-21 11:29 |
2020-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|