|
271151
|
- |
|
fedoraproject redhat opensuse
|
fedora enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_hpc_node opensuse icedtea
|
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving …
|
CWE-20
Improper Input Validation
|
CVE-2015-5235
|
2024-11-21 11:32 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271152
|
- |
|
redhat opensuse fedoraproject
|
enterprise_linux_hpc_node enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation opensuse icedtea fedora
|
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass use…
|
CWE-20
Improper Input Validation
|
CVE-2015-5234
|
2024-11-21 11:32 |
2015-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271153
|
- |
|
ibm
|
emptoris_sourcing
|
IBM Emptoris Sourcing 10.0.2.0 before iFix6, 10.0.2.2 before iFix11, 10.0.2.3, 10.0.2.5 before iFix4, 10.0.2.6 before iFix8, 10.0.2.7 before iFix1, and 10.0.4.x before iFix2 allows remote authenticat…
|
CWE-200
Information Exposure
|
CVE-2015-5024
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271154
|
- |
|
ibm
|
b2b_advanced_communications
|
IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2, when access by guests is enabled, place an internal hostname and a p…
|
CWE-200
Information Exposure
|
CVE-2015-5022
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271155
|
- |
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator 5.2 before 5020500_8 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2015-4992
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271156
|
- |
|
ibm
|
b2b_advanced_communications
|
Cross-site scripting (XSS) vulnerability in IBM Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 and 1.0.0.3 before 1.0.0.3_2 allows remote attackers t…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4973
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271157
|
- |
|
ibm
|
emptoris emptoris_program_management
|
Cross-site scripting (XSS) vulnerability in IBM Emptoris Strategic Supply Management Platform and Emptoris Program Management 10.x before 10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x befo…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4971
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271158
|
- |
|
ibm
|
maximo_asset_management maximo_for_nuclear_power maximo_for_utilities maximo_for_life_sciences maximo_for_oil_and_gas maximo_for_transportation maximo_for_government smartcloud_c…
|
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 a…
|
CWE-89
SQL Injection
|
CVE-2015-4967
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271159
|
- |
|
ibm
|
maximo_asset_management maximo_for_nuclear_power maximo_for_utilities maximo_for_life_sciences maximo_for_oil_and_gas maximo_for_transportation maximo_for_government smartcloud_c…
|
maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x b…
|
CWE-200
Information Exposure
|
CVE-2015-4965
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271160
|
- |
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allows remote authenticated users to gain privileges by…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-4964
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|