|
270721
|
9.8 |
CRITICAL
Network
|
redhat apache fedoraproject
|
openshift activemq fedora
|
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Ser…
|
CWE-20
Improper Input Validation
|
CVE-2015-5254
|
2024-11-21 11:32 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270722
|
4.3 |
MEDIUM
Adjacent
|
google
|
android
|
The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers …
|
CWE-200
Information Exposure
|
CVE-2015-5310
|
2024-11-21 11:32 |
2016-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270723
|
4.3 |
MEDIUM
Network
|
ibm
|
maximo_for_transportation maximo_for_utilities maximo_asset_management smartcloud_control_desk maximo_for_life_sciences maximo_asset_management_essentials maximo_for_nuclear_power
|
IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.2 IF1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.5.1, and 7.6 before 7.6.0.2 IF1 for SmartCloud Control Desk allow r…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5051
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270724
|
7.5 |
HIGH
Network
|
ibm
|
connections
|
IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 does not properly detect recursion during XML entity expansion, which allows remote attackers to cause a den…
|
NVD-CWE-Other
|
CVE-2015-5038
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270725
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site request forgery (CSRF) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to hijack the authentic…
|
CWE-352
Origin Validation Error
|
CVE-2015-5037
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270726
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5036
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270727
|
5.4 |
MEDIUM
Network
|
ibm
|
connections
|
Cross-site scripting (XSS) vulnerability in IBM Connections 3.x before 3.0.1.1 CR3, 4.0 before CR4, 4.5 before CR5, and 5.0 before CR3 allows remote authenticated users to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5035
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270728
|
5.4 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
SQL injection vulnerability in IBM Curam Social Program Management 6.1 before 6.1.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2015-5023
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270729
|
5.4 |
MEDIUM
Network
|
ibm
|
maximo_for_transportation maximo_for_utilities maximo_for_nuclear_power tivoli_service_request_manager maximo_asset_management smartcloud_control_desk maximo_for_life_sciences ch…
|
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX005, and 7.6.0 before 7.6.0.2 IFIX002; Maximo Asset Management 7.5.0 before 7.5.0.8 IFIX005, 7.5.1, and 7.6.0 before 7.6.0.2…
|
CWE-284
Improper Access Control
|
CVE-2015-5017
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270730
|
8.5 |
HIGH
Network
|
ibm
|
tivoli_monitoring
|
The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arbitrary commands by leveraging Take Action view aut…
|
CWE-77
Command Injection
|
CVE-2015-5003
|
2024-11-21 11:32 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|