|
270751
|
- |
|
canonical redhat apple xmlsoft hp debian
|
ubuntu_linux enterprise_linux_hpc_node enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation watchos iphone_os mac_os_x tvos libxml2 icewall_file…
|
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU cons…
|
CWE-399
Resource Management Errors
|
CVE-2015-5312
|
2024-11-21 11:32 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270752
|
- |
|
ibm
|
websphere_application_server
|
The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 does not properly encrypt data, which allows remote authenticated users to obtain…
|
CWE-200
Information Exposure
|
CVE-2015-5004
|
2024-11-21 11:32 |
2015-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270753
|
- |
|
opensuse simon_tatham
|
leap opensuse putty
|
Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via an ECH (erase characters…
|
CWE-189
Numeric Errors
|
CVE-2015-5309
|
2024-11-21 11:32 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270754
|
- |
|
ibm redhat suse
|
java_2_sdk java_sdk enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation satellite enterprise_linux_server_eus linux_enterprise_server linux_enterpris…
|
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attacke…
|
CWE-200
Information Exposure
|
CVE-2015-5006
|
2024-11-21 11:32 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270755
|
- |
|
redhat
|
libreport
|
libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1)…
|
CWE-200
Information Exposure
|
CVE-2015-5302
|
2024-11-21 11:32 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270756
|
- |
|
redhat
|
automatic_bug_reporting_tool enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable na…
|
CWE-59
Link Following
|
CVE-2015-5287
|
2024-11-21 11:32 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270757
|
- |
|
redhat
|
automatic_bug_reporting_tool enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users to write to arbitrary files via a symlink attack on unpacked.cpio i…
|
CWE-59
Link Following
|
CVE-2015-5273
|
2024-11-21 11:32 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270758
|
- |
|
redhat
|
ceph
|
CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks…
|
NVD-CWE-Other
|
CVE-2015-5245
|
2024-11-21 11:32 |
2015-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270759
|
- |
|
jenkins redhat
|
jenkins openshift
|
Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5326
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270760
|
- |
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: this vulnerability exists because of an incomplete…
|
CWE-284
Improper Access Control
|
CVE-2015-5325
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|