|
269331
|
5.3 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
The "Project Documentation" feature in MantisBT 1.2.19 and earlier, when the threshold to access files ($g_view_proj_doc_threshold) is set to ANYBODY, allows remote authenticated users to download at…
|
CWE-200
Information Exposure
|
CVE-2015-5059
|
2024-11-21 11:32 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269332
|
6.7 |
MEDIUM
Local
|
vmware
|
tools
|
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privil…
|
CWE-362
Race Condition
|
CVE-2015-5191
|
2024-11-21 11:32 |
2017-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269333
|
5.5 |
MEDIUM
Local
|
fedoraproject opensuse_project opensuse jasper_project
|
fedora leap opensuse jasper
|
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) vi…
|
CWE-416
Use After Free
|
CVE-2015-5221
|
2024-11-21 11:32 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269334
|
6.5 |
MEDIUM
Network
|
candlepinproject
|
candlepin
|
Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.
|
CWE-200 CWE-399
Information Exposure Resource Management Errors
|
CVE-2015-5187
|
2024-11-21 11:32 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269335
|
7.5 |
HIGH
Network
|
fedoraproject suse opensuse redhat debian canonical ntp
|
fedora linux_enterprise_server manager_proxy linux_enterprise_debuginfo linux_enterprise_software_development_kit manager openstack_cloud linux_enterprise_desktop leap open…
|
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to…
|
CWE-361
7PK - Time and State
|
CVE-2015-5300
|
2024-11-21 11:32 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269336
|
7.5 |
HIGH
Network
|
fedoraproject suse redhat debian canonical ntp novell opensuse siemens oracle
|
fedora manager_proxy linux_enterprise_debuginfo manager linux_enterprise_server openstack_cloud enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infin…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2015-5219
|
2024-11-21 11:32 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269337
|
7.5 |
HIGH
Network
|
fedoraproject redhat debian canonical ntp
|
fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node debian_linux ubuntu_linux ntp
|
ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled …
|
CWE-20
Improper Input Validation
|
CVE-2015-5195
|
2024-11-21 11:32 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269338
|
7.5 |
HIGH
Network
|
fedoraproject suse redhat debian canonical ntp
|
fedora manager_proxy linux_enterprise_debuginfo manager linux_enterprise_server openstack_cloud enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
|
CWE-20
Improper Input Validation
|
CVE-2015-5194
|
2024-11-21 11:32 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269339
|
8.1 |
HIGH
Network
|
theforeman
|
foreman
|
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-…
|
CWE-200
Information Exposure
|
CVE-2015-5152
|
2024-11-21 11:32 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269340
|
7.5 |
HIGH
Network
|
elasticsearch elastic
|
logstash
|
Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server.
|
CWE-200
Information Exposure
|
CVE-2015-5378
|
2024-11-21 11:32 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|