|
268931
|
6.1 |
MEDIUM
Network
|
misp-project
|
malware_information_sharing_platform
|
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5720
|
2024-11-21 11:33 |
2016-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268932
|
9.8 |
CRITICAL
Network
|
misp-project
|
malware_information_sharing_platform
|
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact a…
|
NVD-CWE-noinfo
|
CVE-2015-5719
|
2024-11-21 11:33 |
2016-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268933
|
7.5 |
HIGH
Network
|
marvell f5
|
software_development_kit traffix_signaling_delivery_controller
|
The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for rem…
|
CWE-200
Information Exposure
|
CVE-2015-5738
|
2024-11-21 11:33 |
2016-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268934
|
6.1 |
MEDIUM
Network
|
qnap
|
qts
|
Cross-site scripting (XSS) vulnerability in File Station in QNAP QTS before 4.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5664
|
2024-11-21 11:33 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268935
|
7.8 |
HIGH
Local
|
zend debian doctrine-project
|
zend-cache debian_linux object_relational_mapper doctrinemongodbbundle zend_framework common annotations mongodb-odm cache zf-apigility-doctrine
|
Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5723
|
2024-11-21 11:33 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268936
|
4.3 |
MEDIUM
Network
|
wordpress
|
wordpress
|
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arra…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5715
|
2024-11-21 11:33 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268937
|
6.1 |
MEDIUM
Network
|
wordpress
|
wordpress
|
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during proces…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5714
|
2024-11-21 11:33 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268938
|
9.8 |
CRITICAL
Network
|
php
|
php
|
The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 does not validate a file pointer before a close operation, which allows…
|
CWE-20
Improper Input Validation
|
CVE-2015-5589
|
2024-11-21 11:33 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268939
|
7.5 |
HIGH
Network
|
botan_project debian
|
botan debian_linux
|
The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, related to a length field.
|
CWE-399
Resource Management Errors
|
CVE-2015-5727
|
2024-11-21 11:33 |
2016-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268940
|
7.5 |
HIGH
Network
|
botan_project debian
|
botan debian_linux
|
The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data.
|
CWE-20
Improper Input Validation
|
CVE-2015-5726
|
2024-11-21 11:33 |
2016-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|