|
271071
|
6.5 |
MEDIUM
Network
|
redhat php
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_node_eus php enterprise_l…
|
PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted i…
|
CWE-20
Improper Input Validation
|
CVE-2015-4598
|
2024-11-21 11:31 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271072
|
- |
|
oracle
|
enterprise_manager_grid_control
|
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 allows remote attackers to affect confidentiality via vectors related to…
|
NVD-CWE-noinfo
|
CVE-2015-4885
|
2024-11-21 11:31 |
2016-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271073
|
- |
|
oracle
|
fusion_middleware
|
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via vectors related to Outside In…
|
NVD-CWE-noinfo
|
CVE-2015-4808
|
2024-11-21 11:31 |
2016-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271074
|
5.3 |
MEDIUM
Network
|
rename_project
|
rename
|
Absolute path traversal vulnerability in mysqldump_download.php in the WordPress Rename plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the dumpfname p…
|
CWE-22
Path Traversal
|
CVE-2015-4703
|
2024-11-21 11:31 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271075
|
6.1 |
MEDIUM
Network
|
opencart
|
opencart
|
Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the zone_id parameter to index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2015-4671
|
2024-11-21 11:31 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271076
|
8.6 |
HIGH
Network
|
zip_attachments_project
|
zip_attachments
|
Directory traversal vulnerability in download.php in the Zip Attachments plugin before 1.5.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the za_file parameter.
|
CWE-22
Path Traversal
|
CVE-2015-4694
|
2024-11-21 11:31 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271077
|
8.0 |
HIGH
Network
|
emc
|
isilon_onefs
|
EMC Isilon OneFS 7.1 before 7.1.1.8, 7.2.0 before 7.2.0.4, and 7.2.1 before 7.2.1.1 allows remote authenticated administrators to bypass a SmartLock root-login restriction by creating a root account …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-4545
|
2024-11-21 11:31 |
2015-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271078
|
- |
|
libreoffice canonical debian apache
|
libreoffice ubuntu_linux debian_linux openoffice
|
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow …
|
CWE-200
Information Exposure
|
CVE-2015-4551
|
2024-11-21 11:31 |
2015-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271079
|
- |
|
mozilla
|
firefox
|
The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism an…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4518
|
2024-11-21 11:31 |
2015-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271080
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox before 42.0, when NTLM v1 is enabled for HTTP authentication, allows remote attackers to obtain sensitive hostname information by constructing a crafted web site that sends an NTLM re…
|
CWE-200
Information Exposure
|
CVE-2015-4515
|
2024-11-21 11:31 |
2015-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|