|
273691
|
- |
|
moodle
|
moodle
|
Directory traversal vulnerability in the min_get_slash_argument function in lib/configonlylib.php in Moodle through 2.5.9, 2.6.x before 2.6.8, 2.7.x before 2.7.5, and 2.8.x before 2.8.3 allows remote…
|
CWE-22
Path Traversal
|
CVE-2015-1493
|
2024-11-21 11:25 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273692
|
- |
|
arubanetworks
|
clearpass_policy_manager
|
Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.4 allows remote administrators to read arbitrary files via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1551
|
2024-11-21 11:25 |
2015-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273693
|
- |
|
arubanetworks
|
clearpass_policy_manager
|
Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administrators to execute arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2015-1550
|
2024-11-21 11:25 |
2015-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273694
|
- |
|
arubanetworks
|
clearpass_policy_manager
|
Multiple SQL injection vulnerabilities in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allow remote administrators to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2015-1392
|
2024-11-21 11:25 |
2015-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273695
|
- |
|
arubanetworks
|
clearpass_policy_manager
|
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote attackers to inject arbitrary web script or HTML via the username parameter to ti…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1389
|
2024-11-21 11:25 |
2015-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273696
|
- |
|
debian google
|
debian_linux chrome
|
Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2015-1265
|
2024-11-21 11:25 |
2015-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273697
|
- |
|
google debian
|
chrome debian_linux
|
Cross-site scripting (XSS) vulnerability in Google Chrome before 43.0.2357.65 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted data that is improperly handled …
|
CWE-79
Cross-site Scripting
|
CVE-2015-1264
|
2024-11-21 11:25 |
2015-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273698
|
- |
|
google debian
|
chrome debian_linux
|
The Spellcheck API implementation in Google Chrome before 43.0.2357.65 does not use an HTTPS session for downloading a Hunspell dictionary, which allows man-in-the-middle attackers to deliver incorre…
|
CWE-17
Code
|
CVE-2015-1263
|
2024-11-21 11:25 |
2015-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273699
|
- |
|
google debian
|
chrome debian_linux
|
platform/fonts/shaping/HarfBuzzShaper.cpp in Blink, as used in Google Chrome before 43.0.2357.65, does not initialize a certain width field, which allows remote attackers to cause a denial of service…
|
CWE-17
Code
|
CVE-2015-1262
|
2024-11-21 11:25 |
2015-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273700
|
- |
|
debian google
|
debian_linux chrome
|
android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use of a URL's fragment identifier during constructio…
|
CWE-20
Improper Input Validation
|
CVE-2015-1261
|
2024-11-21 11:25 |
2015-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|