|
268871
|
- |
|
djangoproject oracle canonical
|
django solaris ubuntu_linux
|
contrib.sessions.middleware.SessionMiddleware in Django 1.8.x before 1.8.4, 1.7.x before 1.7.10, 1.4.x before 1.4.22, and possibly other versions allows remote attackers to cause a denial of service …
|
CWE-399
Resource Management Errors
|
CVE-2015-5963
|
2024-11-21 11:34 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268872
|
- |
|
cisco
|
wireless_lan_controller_software
|
The Internet Access Point Protocol (IAPP) module on Cisco Wireless LAN Controller (WLC) devices with software 8.1(104.37) allows remote attackers to trigger incorrect traffic forwarding via crafted I…
|
CWE-20
Improper Input Validation
|
CVE-2015-6258
|
2024-11-21 11:34 |
2015-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268873
|
- |
|
cisco
|
asr_5000_series_software
|
Cisco ASR 5000 devices with software 19.0.M0.60828 allow remote attackers to cause a denial of service (OSPF process restart) via crafted length fields in headers of OSPF packets, aka Bug ID CSCuv628…
|
CWE-20
Improper Input Validation
|
CVE-2015-6256
|
2024-11-21 11:34 |
2015-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268874
|
- |
|
cisco
|
unified_web_and_e-mail_interaction_manager
|
Cross-site scripting (XSS) vulnerability in Cisco Unified Web and E-Mail Interaction Manager 9.0(2) allows remote attackers to inject arbitrary web script or HTML via a crafted chat message, aka Bug …
|
CWE-79
Cross-site Scripting
|
CVE-2015-6255
|
2024-11-21 11:34 |
2015-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268875
|
- |
|
picketlink
|
picketlink
|
The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a Response element in a SAML assertion matches the location …
|
CWE-17
Code
|
CVE-2015-6254
|
2024-11-21 11:34 |
2015-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268876
|
- |
|
fortinet
|
fortios
|
The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remote attackers to spoof encrypted content via a craft…
|
CWE-20
Improper Input Validation
|
CVE-2015-5965
|
2024-11-21 11:34 |
2015-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268877
|
- |
|
mozilla
|
firefox_os
|
Integer signedness error in the SharedBufferManagerParent::RecvAllocateGrallocBuffer function in the buffer-management implementation in the graphics layer in Mozilla Firefox OS before 2.2 might allo…
|
CWE-189
Numeric Errors
|
CVE-2015-5962
|
2024-11-21 11:34 |
2015-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268878
|
- |
|
mozilla
|
firefox_os
|
The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5961
|
2024-11-21 11:34 |
2015-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268879
|
- |
|
mozilla
|
firefox_os
|
Mozilla Firefox OS before 2.2 allows physically proximate attackers to bypass the pass-code protection mechanism and access USB Mass Storage (UMS) media volumes by using the USB interface for a mount…
|
CWE-284
Improper Access Control
|
CVE-2015-5960
|
2024-11-21 11:34 |
2015-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268880
|
9.8 |
CRITICAL
Network
|
yiiframework
|
yii
|
web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.
|
CWE-22
Path Traversal
|
CVE-2015-5467
|
2024-11-21 11:33 |
2023-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|