|
271221
|
- |
|
moodle
|
moodle
|
Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and con…
|
NVD-CWE-Other
|
CVE-2015-3175
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271222
|
- |
|
moodle
|
moodle
|
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to c…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3174
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271223
|
- |
|
zenphoto
|
zenphoto
|
Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2949
|
2024-11-21 11:28 |
2015-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271224
|
- |
|
zenphoto
|
zenphoto
|
Cross-site scripting (XSS) vulnerability in the image processor in Zenphoto before 1.4.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2948
|
2024-11-21 11:28 |
2015-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271225
|
- |
|
blue_coat
|
ssl_visibility_appliance_sv800_firmware ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv3800_firmware ssl_visibility_appliance_sv2800_firmware
|
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not set the secure flag for the administrator's cookie in an https se…
|
CWE-200
Information Exposure
|
CVE-2015-2855
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271226
|
- |
|
blue_coat
|
ssl_visibility_appliance_sv800_firmware ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv2800_firmware ssl_visibility_appliance_sv3800_firmware
|
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not send a restrictive X-Frame-Options HTTP header, which allows remo…
|
CWE-20
Improper Input Validation
|
CVE-2015-2854
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271227
|
- |
|
blue_coat
|
ssl_visibility_appliance_sv3800_firmware ssl_visibility_appliance_sv2800_firmware ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv800_firmware
|
Session fixation vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers to hijack web se…
|
NVD-CWE-Other
|
CVE-2015-2853
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271228
|
- |
|
blue_coat
|
ssl_visibility_appliance_sv2800_firmware ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv3800_firmware ssl_visibility_appliance_sv800_firmware
|
Cross-site request forgery (CSRF) vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers…
|
CWE-352
Origin Validation Error
|
CVE-2015-2852
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271229
|
- |
|
synology
|
cloud_station
|
client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change the ownership of arbitrary files, and consequently obtain root access, by spec…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2851
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271230
|
- |
|
canonical debian apple postgresql
|
ubuntu_linux debian_linux mac_os_x_server postgresql
|
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash…
|
NVD-CWE-Other
|
CVE-2015-3165
|
2024-11-21 11:28 |
2015-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|