|
272891
|
- |
|
searchblox
|
searchblox
|
Multiple cross-site scripting (XSS) vulnerabilities in SearchBlox before 8.2 allow remote attackers to inject arbitrary web script or HTML via (1) the search field in plugin/index.html or (2) the tit…
|
CWE-79
Cross-site Scripting
|
CVE-2015-0967
|
2024-11-21 11:24 |
2015-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272892
|
- |
|
blue_coat
|
malware_analysis_appliance
|
search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attackers to bypass intended access restrictions, and list or read arbitrary documents…
|
CWE-200
Information Exposure
|
CVE-2015-0938
|
2024-11-21 11:24 |
2015-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272893
|
- |
|
blue_coat
|
malware_analysis_appliance
|
Cross-site scripting (XSS) vulnerability in search.php on the Blue Coat Malware Analysis appliance with software before 4.2.4.20150312-RELEASE allows remote attackers to inject arbitrary web script o…
|
CWE-79
Cross-site Scripting
|
CVE-2015-0937
|
2024-11-21 11:24 |
2015-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272894
|
- |
|
apple
|
xcode
|
Integer overflow in the simulator in Swift in Apple Xcode before 6.3 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact by triggering an incorre…
|
CWE-189
Numeric Errors
|
CVE-2015-1149
|
2024-11-21 11:24 |
2015-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272895
|
- |
|
apple
|
mac_os_x
|
Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-dependent attackers to obtain sensitive information by reading this file.
|
CWE-200
Information Exposure
|
CVE-2015-1148
|
2024-11-21 11:24 |
2015-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272896
|
- |
|
apple
|
mac_os_x
|
Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates, which allows remote attackers to obtain sensitiv…
|
CWE-200
Information Exposure
|
CVE-2015-1147
|
2024-11-21 11:24 |
2015-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272897
|
- |
|
apple
|
mac_os_x
|
The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different v…
|
CWE-310
Cryptographic Issues
|
CVE-2015-1146
|
2024-11-21 11:24 |
2015-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272898
|
- |
|
apple
|
mac_os_x
|
The Code Signing implementation in Apple OS X before 10.10.3 does not properly validate signatures, which allows local users to bypass intended access restrictions via a crafted bundle, a different v…
|
CWE-310
Cryptographic Issues
|
CVE-2015-1145
|
2024-11-21 11:24 |
2015-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272899
|
- |
|
apple
|
mac_os_x
|
Buffer overflow in the UniformTypeIdentifiers component in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted Uniform Type Identifier.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-1144
|
2024-11-21 11:24 |
2015-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272900
|
- |
|
apple
|
mac_os_x
|
LaunchServices in Apple OS X before 10.10.3 allows local users to gain privileges via a crafted localized string, related to a "type confusion" issue.
|
NVD-CWE-Other
|
CVE-2015-1143
|
2024-11-21 11:24 |
2015-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|