|
272061
|
8.8 |
HIGH
Network
|
phpbugtracker_project
|
phpbugtracker
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authentication of users for requests that cause an unspecifi…
|
CWE-352
Origin Validation Error
|
CVE-2015-2143
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272062
|
8.0 |
HIGH
Network
|
phpbugtracker_project
|
phpbugtracker
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to (1) hijack the authentication of users for requests that caus…
|
CWE-352
Origin Validation Error
|
CVE-2015-2142
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272063
|
5.9 |
MEDIUM
Network
|
http.rb_project
|
http.rb
|
The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack.
|
CWE-200
Information Exposure
|
CVE-2015-1828
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272064
|
7.8 |
HIGH
Local
|
pngcrush_project
|
pngcrush
|
Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary c…
|
CWE-189
Numeric Errors
|
CVE-2015-2158
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272065
|
6.1 |
MEDIUM
Network
|
emberjs
|
ember.js
|
Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1866
|
2024-11-21 11:26 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272066
|
4.7 |
MEDIUM
Local
|
gnu
|
coreutils
|
fts.c in coreutils 8.4 allows local users to delete arbitrary files.
|
CWE-362
Race Condition
|
CVE-2015-1865
|
2024-11-21 11:26 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272067
|
5.9 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform
|
AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential pas…
|
CWE-200
Information Exposure
|
CVE-2015-1849
|
2024-11-21 11:26 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272068
|
5.4 |
MEDIUM
Network
|
kallithea-scm
|
kallithea
|
Multiple cross-site scripting (XSS) vulnerabilities in the administration pages in Kallithea before 0.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) l…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1864
|
2024-11-21 11:26 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272069
|
7.5 |
HIGH
Network
|
fedoraproject debian
|
389_directory_server fedora debian_linux
|
389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
|
CWE-284
Improper Access Control
|
CVE-2015-1854
|
2024-11-21 11:26 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272070
|
6.1 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and later before 1.2.20.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2046
|
2024-11-21 11:26 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|