|
272281
|
8.1 |
HIGH
Network
|
linuxcontainers
|
lxd
|
LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause a…
|
CWE-362
Race Condition
|
CVE-2015-1340
|
2024-11-21 11:25 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272282
|
7.8 |
HIGH
Local
|
canonical
|
ubuntu_linux
|
Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transf…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1327
|
2024-11-21 11:25 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272283
|
8.8 |
HIGH
Network
|
python-dbusmock_project
|
python-dbusmock
|
python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method could be tricked into executing malicious code if an attacker supplies a .pyc file.
|
CWE-20
Improper Input Validation
|
CVE-2015-1326
|
2024-11-21 11:25 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272284
|
9.8 |
CRITICAL
Network
|
canonical
|
metal_as_a_service
|
The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface. This issue affects Ubuntu MAAS versions prior to 1.9.2.
|
CWE-255
Credentials Management
|
CVE-2015-1320
|
2024-11-21 11:25 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272285
|
7.5 |
HIGH
Network
|
canonical
|
juju
|
Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.
|
CWE-320
Key Management Errors
|
CVE-2015-1316
|
2024-11-21 11:25 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272286
|
7.5 |
HIGH
Network
|
icewarp
|
mail_server
|
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/d…
|
CWE-22
Path Traversal
|
CVE-2015-1503
|
2024-11-21 11:25 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272287
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1 before 10.2-RC1-p2, and 0.2-RC2 before 10.2-RC2-p…
|
CWE-200
Information Exposure
|
CVE-2015-1418
|
2024-11-21 11:25 |
2018-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272288
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5; and possibly other patch variants allow …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1416
|
2024-11-21 11:25 |
2018-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272289
|
8.8 |
HIGH
Network
|
google qt opensuse
|
chrome qt leap
|
The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause a denial of service (memory corruption) or execute arbitrar…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-1290
|
2024-11-21 11:25 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272290
|
7.5 |
HIGH
Network
|
cybelesoft
|
thinfinity_remote_desktop_workstation
|
Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit allows remote attackers to download arbitrary files via a .. (dot dot) in an unspe…
|
CWE-22
Path Traversal
|
CVE-2015-1429
|
2024-11-21 11:25 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|