|
273391
|
- |
|
shibboleth debian
|
service_provider debian_linux
|
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.
|
CWE-20
Improper Input Validation
|
CVE-2015-2684
|
2024-11-21 11:27 |
2015-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273392
|
- |
|
nih php fedoraproject debian opensuse
|
libzip php fedora debian_linux opensuse
|
Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other p…
|
CWE-189
Numeric Errors
|
CVE-2015-2331
|
2024-11-21 11:27 |
2015-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273393
|
- |
|
redhat apple opensuse php
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_node_eus mac_os_x opensus…
|
The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, whic…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2348
|
2024-11-21 11:27 |
2015-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273394
|
- |
|
rxspencer_project debian canonical opensuse php
|
rxspencer debian_linux ubuntu_linux opensuse php
|
Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2015-2305
|
2024-11-21 11:27 |
2015-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273395
|
- |
|
canonical debian opensuse php apple redhat
|
ubuntu_linux debian_linux opensuse php mac_os_x enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_ser…
|
Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have uns…
|
CWE-416
Use After Free
|
CVE-2015-2301
|
2024-11-21 11:27 |
2015-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273396
|
- |
|
websense
|
v-series_appliances triton_ap_data triton_ap_web triton_ap_email
|
Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sensitive information via a direct request to a (1) Web Securi…
|
CWE-200
Information Exposure
|
CVE-2015-2748
|
2024-11-21 11:27 |
2015-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273397
|
- |
|
websense
|
v-series_appliances triton
|
Multiple cross-site scripting (XSS) vulnerabilities in the data loss prevention (DLP) incident Forensics Preview in Websense Triton 7.8.3 and V-Series 7.7 appliances allow remote attackers to inject …
|
CWE-79
Cross-site Scripting
|
CVE-2015-2747
|
2024-11-21 11:27 |
2015-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273398
|
- |
|
websense
|
v-series_appliances triton
|
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticat…
|
CWE-77
Command Injection
|
CVE-2015-2746
|
2024-11-21 11:27 |
2015-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273399
|
- |
|
citrix
|
command_center
|
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX) Servlet, which allows remote attackers to execut…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2683
|
2024-11-21 11:27 |
2015-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273400
|
- |
|
citrix
|
command_center
|
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml.
|
CWE-17
Code
|
CVE-2015-2682
|
2024-11-21 11:27 |
2015-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|