|
269771
|
9.8 |
CRITICAL
Network
|
redhat php
|
enterprise_linux php enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_node…
|
The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (applicat…
|
NVD-CWE-Other
|
CVE-2015-4602
|
2024-11-21 11:31 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269772
|
9.8 |
CRITICAL
Network
|
redhat php
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_node_eus php
|
PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in (1…
|
NVD-CWE-Other
|
CVE-2015-4601
|
2024-11-21 11:31 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269773
|
9.8 |
CRITICAL
Network
|
redhat php
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_node_eus php
|
The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary …
|
NVD-CWE-Other
|
CVE-2015-4600
|
2024-11-21 11:31 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269774
|
9.8 |
CRITICAL
Network
|
php redhat
|
php enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_node_eus
|
The SoapFault::__toString method in ext/soap/soap.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information, cause a denial of servic…
|
NVD-CWE-Other
|
CVE-2015-4599
|
2024-11-21 11:31 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269775
|
6.5 |
MEDIUM
Network
|
redhat php
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_node_eus php enterprise_l…
|
PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted i…
|
CWE-20
Improper Input Validation
|
CVE-2015-4598
|
2024-11-21 11:31 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269776
|
- |
|
oracle
|
enterprise_manager_grid_control
|
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 allows remote attackers to affect confidentiality via vectors related to…
|
NVD-CWE-noinfo
|
CVE-2015-4885
|
2024-11-21 11:31 |
2016-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269777
|
- |
|
oracle
|
fusion_middleware
|
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via vectors related to Outside In…
|
NVD-CWE-noinfo
|
CVE-2015-4808
|
2024-11-21 11:31 |
2016-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269778
|
5.3 |
MEDIUM
Network
|
rename_project
|
rename
|
Absolute path traversal vulnerability in mysqldump_download.php in the WordPress Rename plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the dumpfname p…
|
CWE-22
Path Traversal
|
CVE-2015-4703
|
2024-11-21 11:31 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269779
|
6.1 |
MEDIUM
Network
|
opencart
|
opencart
|
Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the zone_id parameter to index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2015-4671
|
2024-11-21 11:31 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269780
|
8.6 |
HIGH
Network
|
zip_attachments_project
|
zip_attachments
|
Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.
|
CWE-22
Path Traversal
|
CVE-2015-4694
|
2024-11-21 11:31 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|