|
271881
|
5.3 |
MEDIUM
Network
|
apache
|
tika
|
Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.
|
CWE-200
Information Exposure
|
CVE-2015-3271
|
2024-11-21 11:29 |
2016-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271882
|
7.5 |
HIGH
Network
|
x.org
|
xorg-server
|
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutI…
|
CWE-369
Divide By Zero
|
CVE-2015-3418
|
2024-11-21 11:29 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271883
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
mm/memory.c in the Linux kernel before 4.1.4 mishandles anonymous pages, which allows local users to gain privileges or cause a denial of service (page tainting) via a crafted application that trigge…
|
CWE-20
Improper Input Validation
|
CVE-2015-3288
|
2024-11-21 11:29 |
2016-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271884
|
7.5 |
HIGH
Network
|
google
|
android
|
packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypass a DEVICE_POWER permission requirement via a broadcast intent with the PNW.sto…
|
CWE-284
Improper Access Control
|
CVE-2015-3854
|
2024-11-21 11:29 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271885
|
5.3 |
MEDIUM
Network
|
php redhat
|
php enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_node_eus enterprise_l…
|
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an ap…
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2015-3412
|
2024-11-21 11:29 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271886
|
6.5 |
MEDIUM
Network
|
redhat php
|
enterprise_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_node_eus
|
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted in…
|
CWE-20
Improper Input Validation
|
CVE-2015-3411
|
2024-11-21 11:29 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271887
|
6.1 |
MEDIUM
Network
|
apache
|
ofbiz
|
Cross-site scripting (XSS) vulnerability in the DisplayEntityField.getDescription method in ModelFormField.java in Apache OFBiz before 12.04.06 and 13.07.x before 13.07.03 allows remote attackers to …
|
CWE-79
Cross-site Scripting
|
CVE-2015-3268
|
2024-11-21 11:29 |
2016-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271888
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
Multiple cross-site scripting (XSS) vulnerabilities in the SCORM module in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allow remote attackers to inject arbit…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3275
|
2024-11-21 11:29 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271889
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
Cross-site scripting (XSS) vulnerability in the user_get_user_details function in user/lib.php in Moodle through 2.6.11, 2.7.x before 2.7.9, 2.8.x before 2.8.7, and 2.9.x before 2.9.1 allows remote a…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3274
|
2024-11-21 11:29 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271890
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
mod/forum/post.php in Moodle 2.9.x before 2.9.1 does not consider the mod/forum:canposttomygroups capability before authorizing "Post a copy to all groups" actions, which allows remote authenticated …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3273
|
2024-11-21 11:29 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|