|
270591
|
6.1 |
MEDIUM
Network
|
apache
|
ofbiz
|
Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to …
|
CWE-79
Cross-site Scripting
|
CVE-2015-3268
|
2024-11-21 11:29 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270592
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbit…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3275
|
2024-11-21 11:29 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270593
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote a…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3274
|
2024-11-21 11:29 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270594
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3273
|
2024-11-21 11:29 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270595
|
7.4 |
HIGH
Network
|
moodle
|
moodle
|
Open redirect vulnerability in the clean_param function in lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote attackers to redire…
|
NVD-CWE-Other
|
CVE-2015-3272
|
2024-11-21 11:29 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270596
|
- |
|
f5
|
big-iq_security big-ip_application_acceleration_manager big-ip_wan_optimization_manager big-iq_adc big-ip_application_security_manager big-ip_global_traffic_manager big-iq_device
|
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP AAM 11.4.0 before 11.5.3 HF2 and 11.6.0 before 11.6…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3628
|
2024-11-21 11:29 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270597
|
7.5 |
HIGH
Network
|
openldap oracle redhat
|
openldap linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_tus enterprise_linux_server_aus …
|
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be …
|
NVD-CWE-noinfo
|
CVE-2015-3276
|
2024-11-21 11:29 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270598
|
- |
|
apache
|
ambari
|
Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related to changing passwords.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3270
|
2024-11-21 11:29 |
2015-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270599
|
- |
|
polkit_project opensuse
|
polkit opensuse
|
PolicyKit (aka polkit) before 0.113 allows local users to cause a denial of service (memory corruption and polkitd daemon crash) and possibly gain privileges via unspecified vectors, related to "java…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3256
|
2024-11-21 11:29 |
2015-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270600
|
- |
|
polkit_project
|
polkit
|
The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via duplicate action IDs in a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3255
|
2024-11-21 11:29 |
2015-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|