|
272481
|
- |
|
microsoft
|
windows_server_2008 windows_server_2012 windows_rt windows_server_2003 windows_8.1 windows_7 windows_rt_8.1 windows_vista windows_8
|
Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not pro…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1643
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272482
|
- |
|
microsoft
|
project_server
|
Cross-site scripting (XSS) vulnerability in Microsoft Project Server 2010 SP2 and 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePo…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1640
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272483
|
- |
|
microsoft
|
office
|
Cross-site scripting (XSS) vulnerability in Microsoft Office for Mac 2011 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Outlook App for Mac XS…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1639
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272484
|
- |
|
microsoft
|
windows_server_2012
|
Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by l…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1638
|
2024-11-21 11:25 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272485
|
- |
|
freebsd
|
freebsd
|
The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local user…
|
CWE-200
Information Exposure
|
CVE-2015-1415
|
2024-11-21 11:25 |
2015-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272486
|
- |
|
canonical oxide_project
|
ubuntu_linux oxide
|
Use-after-free vulnerability in Oxide before 1.5.6 and 1.6.x before 1.6.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by deleting all WebContents w…
|
NVD-CWE-Other
|
CVE-2015-1317
|
2024-11-21 11:25 |
2015-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272487
|
- |
|
canonical gnu
|
ubuntu_linux glibc
|
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca functi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-1473
|
2024-11-21 11:25 |
2015-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272488
|
- |
|
canonical gnu
|
ubuntu_linux glibc
|
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attac…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-1472
|
2024-11-21 11:25 |
2015-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272489
|
- |
|
siemens
|
simatic_step_7
|
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to determine cleartext (1) protection-leve…
|
CWE-200
Information Exposure
|
CVE-2015-1602
|
2024-11-21 11:25 |
2015-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272490
|
- |
|
siemens
|
simatic_step_7
|
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 allows man-in-the-middle attackers to obtain sensitive information or modify transmitted data via unspecified vectors.
|
CWE-254
7PK - Security Features
|
CVE-2015-1601
|
2024-11-21 11:25 |
2015-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|