|
270521
|
- |
|
concrete5
|
concrete5
|
Multiple cross-site scripting (XSS) vulnerabilities in concrete5 before 5.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to private messages or other unspecifie…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3989
|
2024-11-21 11:30 |
2015-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270522
|
- |
|
mcafee
|
epo_deep_command
|
Multiple unquoted Windows search path vulnerabilities in the (1) Client Management and (2) Gateway in McAfee ePO Deep Command 2.1 and 2.2 before HF 1058831 allow local users to gain privileges via un…
|
CWE-426
Untrusted Search Path
|
CVE-2015-3987
|
2024-11-21 11:30 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270523
|
- |
|
thecartpress
|
thecartpress_ecommerce_shopping_cart
|
Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attacke…
|
CWE-352
Origin Validation Error
|
CVE-2015-3986
|
2024-11-21 11:30 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270524
|
- |
|
fedora
|
pacemaker_configuration_system
|
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via …
|
CWE-310
Cryptographic Issues
|
CVE-2015-3983
|
2024-11-21 11:30 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270525
|
- |
|
sap
|
netweaver_rfc_sdk
|
SAP NetWeaver RFC SDK allows attackers to obtain sensitive information via unspecified vectors, aka SAP Security Note 2084037.
|
CWE-200
Information Exposure
|
CVE-2015-3981
|
2024-11-21 11:30 |
2015-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270526
|
- |
|
sap
|
customer_relationship_management
|
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.
|
CWE-89
SQL Injection
|
CVE-2015-3980
|
2024-11-21 11:30 |
2015-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270527
|
- |
|
sap
|
customer_relationship_management
|
Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.
|
NVD-CWE-noinfo
|
CVE-2015-3979
|
2024-11-21 11:30 |
2015-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270528
|
- |
|
sap
|
sybase_unwired_platform_online_data_proxy
|
SAP Sybase Unwired Platform Online Data Proxy allows local users to obtain usernames and passwords via the DataVault, aka SAP Security Note 2094830.
|
CWE-200
Information Exposure
|
CVE-2015-3978
|
2024-11-21 11:30 |
2015-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270529
|
8.8 |
HIGH
Adjacent
|
yubico
|
ykneo-openpgp
|
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2015-3298
|
2024-11-21 11:29 |
2022-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270530
|
7.5 |
HIGH
Network
|
bitcoin
|
bitcoin_core
|
bitcoind and Bitcoin-Qt prior to 0.10.2 allow attackers to cause a denial of service (disabled functionality such as a client application crash) via an "Easy" attack.
|
NVD-CWE-noinfo
|
CVE-2015-3641
|
2024-11-21 11:29 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|