|
275091
|
- |
|
sap
|
afaria
|
SAP Afaria does not properly restrict access to unspecified functionality, which allows remote attackers to obtain sensitive information, gain privileges, or have other unspecified impact via unknown…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-4161
|
2024-11-21 11:30 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275092
|
- |
|
sap
|
ase_database_platform
|
SQL injection vulnerability in SAP ASE Database Platform allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Notes: 2152278.
|
CWE-89
SQL Injection
|
CVE-2015-4160
|
2024-11-21 11:30 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275093
|
- |
|
sap
|
hana_web-based_development_workbench
|
SQL injection vulnerability in SAP HANA Web-based Development Workbench allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Notes 2153892.
|
CWE-89
SQL Injection
|
CVE-2015-4159
|
2024-11-21 11:30 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275094
|
- |
|
sap
|
netweaver_java_application_server netweaver_abap_application_server
|
SAP ABAP & Java Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2121661.
|
NVD-CWE-noinfo
|
CVE-2015-4158
|
2024-11-21 11:30 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275095
|
- |
|
sap
|
content_server
|
SAP Content Server allows remote attackers to cause a denial of service (service termination) via unspecified vectors, aka SAP Security Note 2127995.
|
NVD-CWE-noinfo
|
CVE-2015-4157
|
2024-11-21 11:30 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275096
|
- |
|
opensuse gnu
|
opensuse parallel
|
GNU Parallel before 20150522 (Nepal), when using (1) --cat or (2) --fifo with --sshlogin, allows local users to write to arbitrary files via a symlink attack on a temporary file.
|
CWE-59
Link Following
|
CVE-2015-4156
|
2024-11-21 11:30 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275097
|
- |
|
gnu
|
parallel
|
GNU Parallel before 20150422, when using (1) --pipe, (2) --tmux, (3) --cat, (4) --fifo, or (5) --compress, allows local users to write to arbitrary files via a symlink attack on a temporary file.
|
CWE-59
Link Following
|
CVE-2015-4155
|
2024-11-21 11:30 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275098
|
- |
|
thycotic
|
secret_server
|
The Thycotic Password Manager Secret Server application through 2.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain s…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-4094
|
2024-11-21 11:30 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275099
|
- |
|
sensiolabs
|
symfony
|
FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if …
|
CWE-284
Improper Access Control
|
CVE-2015-4050
|
2024-11-21 11:30 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275100
|
- |
|
djangoproject
|
django
|
The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not properly flush the session, which allows remote attackers to hijack user sessions via an empty string in the …
|
NVD-CWE-Other
|
CVE-2015-3982
|
2024-11-21 11:30 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|