|
270521
|
9.8 |
CRITICAL
Network
|
golang fedoraproject redhat
|
go fedora enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_server enterprise_linux_server_eus
|
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instea…
|
CWE-444
HTTP Request Smuggling
|
CVE-2015-5739
|
2024-11-21 11:33 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270522
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The sys_amd64 IRET Handler in the kernel in FreeBSD 9.3 and 10.1 allows local users to gain privileges or cause a denial of service (kernel panic).
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5675
|
2024-11-21 11:33 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270523
|
7.4 |
HIGH
Network
|
dwango
|
niconico
|
niconico App for iOS before 6.38 does not verify SSL certificates which could allow remote attackers to execute man-in-the-middle attacks.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-5639
|
2024-11-21 11:33 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270524
|
5.4 |
MEDIUM
Network
|
octobercms
|
october
|
Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving a file title, a different vulnerabil…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5613
|
2024-11-21 11:33 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270525
|
7.8 |
HIGH
Local
|
devscripts_devel_team fedoraproject
|
devscripts fedora
|
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
|
CWE-77
Command Injection
|
CVE-2015-5704
|
2024-11-21 11:33 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270526
|
5.9 |
MEDIUM
Network
|
ana
|
all_nippon_airways
|
ANA App for Android 3.1.1 and earlier, and ANA App for iOS 3.3.6 and earlier does not verify SSL certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-5666
|
2024-11-21 11:33 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270527
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
|
CWE-601
Open Redirect
|
CVE-2015-5608
|
2024-11-21 11:33 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270528
|
8.8 |
HIGH
Network
|
ipython fedoraproject
|
ipython fedora
|
Cross-site request forgery in the REST API in IPython 2 and 3.
|
CWE-352
Origin Validation Error
|
CVE-2015-5607
|
2024-11-21 11:33 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270529
|
7.5 |
HIGH
Network
|
devscripts_devel_team fedoraproject
|
devscripts fedora
|
Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename.
|
CWE-59
Link Following
|
CVE-2015-5705
|
2024-11-21 11:33 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270530
|
6.5 |
MEDIUM
Network
|
openstack
|
designate
|
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-5695
|
2024-11-21 11:33 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|