|
269341
|
7.5 |
HIGH
Network
|
canonical gnu
|
ubuntu_linux glibc
|
res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-5180
|
2024-11-21 11:32 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269342
|
8.1 |
HIGH
Network
|
cornelisnetworks
|
opa-ff opa-fm
|
Race conditions in opa-fm before 10.4.0.0.196 and opa-ff before 10.4.0.0.197.
|
CWE-362
Race Condition
|
CVE-2015-5232
|
2024-11-21 11:32 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269343
|
7.5 |
HIGH
Network
|
apache
|
cxf_fediz
|
Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2015-5175
|
2024-11-21 11:32 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269344
|
9.6 |
CRITICAL
Network
|
vmware debian
|
spring_framework debian_linux
|
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2015-5211
|
2024-11-21 11:32 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269345
|
7.5 |
HIGH
Network
|
teradata
|
teradata_express teradata_gateway
|
Teradata Gateway before 15.00.03.02-1 and 15.10.x before 15.10.00.01-1 and TD Express before 15.00.02.08_Sles10 and 15.00.02.08_Sles11 allow remote attackers to cause a denial of service (database cr…
|
CWE-20
Improper Input Validation
|
CVE-2015-5401
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269346
|
7.5 |
HIGH
Network
|
roundcube
|
roundcube_webmail webmail
|
Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.
|
CWE-200
Information Exposure
|
CVE-2015-5383
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269347
|
6.5 |
MEDIUM
Network
|
roundcube
|
roundcube_webmail webmail
|
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
|
CWE-200
Information Exposure
|
CVE-2015-5382
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269348
|
6.1 |
MEDIUM
Network
|
roundcube
|
roundcube_webmail webmail
|
Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter t…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5381
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269349
|
6.1 |
MEDIUM
Network
|
apache
|
juddi
|
After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect the browser to an unintended web page in Apache j…
|
CWE-601
Open Redirect
|
CVE-2015-5241
|
2024-11-21 11:32 |
2017-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269350
|
5.5 |
MEDIUM
Local
|
ibm
|
security_access_manager_for_web_8.0_firmware security_access_manager_for_mobile security_access_manager_9.0_firmware
|
The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2015-5013
|
2024-11-21 11:32 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|