|
269291
|
9.8 |
CRITICAL
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cf-release
|
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire …
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2015-5172
|
2024-11-21 11:32 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269292
|
9.8 |
CRITICAL
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cf-release
|
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified im…
|
CWE-613
Insufficient Session Expiration
|
CVE-2015-5171
|
2024-11-21 11:32 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269293
|
8.8 |
HIGH
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cloud_foundry_uaa cf-release
|
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks…
|
CWE-352
Origin Validation Error
|
CVE-2015-5170
|
2024-11-21 11:32 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269294
|
5.4 |
MEDIUM
Network
|
axigen
|
axigen_mail_server
|
Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackers to inject arbitrary web script or HTML via an email atta…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5379
|
2024-11-21 11:32 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269295
|
7.5 |
HIGH
Network
|
openslp debian
|
openslp debian_linux
|
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
|
CWE-415
Double Free
|
CVE-2015-5177
|
2024-11-21 11:32 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269296
|
9.8 |
CRITICAL
Network
|
gsi-office
|
winpat_portal
|
SQL injection vulnerability in the login form in GSI WiNPAT Portal 3.2.0.1001 through 3.6.1.0 allows remote attackers to execute arbitrary SQL commands via the username field.
|
CWE-89
SQL Injection
|
CVE-2015-5376
|
2024-11-21 11:32 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269297
|
8.8 |
HIGH
Network
|
inboundnow
|
wordpress_landing_pages
|
The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter.
|
CWE-74
Injection
|
CVE-2015-5227
|
2024-11-21 11:32 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269298
|
7.2 |
HIGH
Network
|
pulpproject
|
qpid
|
The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2015-5164
|
2024-11-21 11:32 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269299
|
8.1 |
HIGH
Network
|
theforeman
|
foreman
|
The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.
|
CWE-254
7PK - Security Features
|
CVE-2015-5246
|
2024-11-21 11:32 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269300
|
3.1 |
LOW
Network
|
wesnoth fedoraproject
|
battle_for_wesnoth fedora
|
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insens…
|
CWE-200
Information Exposure
|
CVE-2015-5070
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|