|
271291
|
- |
|
owncloud
|
owncloud
|
ownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbitrary files via a file path with UTF-8 encoding, as…
|
CWE-74
Injection
|
CVE-2015-3013
|
2024-11-21 11:28 |
2015-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271292
|
- |
|
debian kogmbh
|
debian_linux webodf
|
Multiple cross-site scripting (XSS) vulnerabilities in WebODF before 0.5.5, as used in ownCloud, allow remote attackers to inject arbitrary web script or HTML via a (1) style or (2) font name or (3) …
|
CWE-79
Cross-site Scripting
|
CVE-2015-3012
|
2024-11-21 11:28 |
2015-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271293
|
- |
|
owncloud debian
|
owncloud debian_linux
|
Multiple cross-site scripting (XSS) vulnerabilities in the contacts application in ownCloud Server Community Edition before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allow remote authenticated u…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3011
|
2024-11-21 11:28 |
2015-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271294
|
- |
|
oracle haxx canonical apple debian
|
enterprise_manager_ops_center libcurl curl ubuntu_linux mac_os_x debian_linux
|
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information…
|
CWE-200
Information Exposure
|
CVE-2015-3153
|
2024-11-21 11:28 |
2015-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271295
|
- |
|
xiph debian opensuse
|
icecast debian_linux opensuse
|
Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without log…
|
NVD-CWE-Other
|
CVE-2015-3026
|
2024-11-21 11:28 |
2015-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271296
|
- |
|
fedoraproject canonical debian apple haxx hp opensuse
|
fedora ubuntu_linux debian_linux mac_os_x libcurl system_management_homepage curl opensuse
|
cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
|
CWE-284
Improper Access Control
|
CVE-2015-3148
|
2024-11-21 11:28 |
2015-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271297
|
- |
|
fedoraproject canonical debian haxx apple oracle hp opensuse
|
fedora ubuntu_linux debian_linux curl mac_os_x solaris libcurl system_management_homepage opensuse
|
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3145
|
2024-11-21 11:28 |
2015-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271298
|
- |
|
oracle haxx canonical debian
|
mysql_enterprise_monitor curl libcurl ubuntu_linux debian_linux
|
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3144
|
2024-11-21 11:28 |
2015-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271299
|
- |
|
haxx canonical debian hp apple
|
curl ubuntu_linux debian_linux libcurl system_management_homepage mac_os_x
|
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3143
|
2024-11-21 11:28 |
2015-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271300
|
- |
|
simple_ads_manager_project
|
simple_ads_manager
|
Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an…
|
NVD-CWE-Other
|
CVE-2015-2825
|
2024-11-21 11:28 |
2015-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|