|
273951
|
- |
|
freereprintables
|
articlefr
|
Cross-site scripting (XSS) vulnerability in Free Reprintables ArticleFR 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter to search/v/.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1363
|
2024-11-21 11:25 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273952
|
- |
|
two_pilots
|
exif_pilot
|
Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary code via a long string in the maker element in an XML file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-1362
|
2024-11-21 11:25 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273953
|
- |
|
google
|
chrome
|
platform/image-decoders/ImageFrame.h in Blink, as used in Google Chrome before 40.0.2214.91, does not initialize a variable that is used in calls to the Skia SkBitmap::setAlphaType function, which mi…
|
CWE-17
Code
|
CVE-2015-1361
|
2024-11-21 11:25 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273954
|
- |
|
google
|
chrome
|
Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data that is improper…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-1360
|
2024-11-21 11:25 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273955
|
- |
|
google
|
chrome
|
Multiple off-by-one errors in fpdfapi/fpdf_font/font_int.h in PDFium, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (buffer overflow) or possibly h…
|
CWE-189
Numeric Errors
|
CVE-2015-1359
|
2024-11-21 11:25 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273956
|
- |
|
kde
|
plasma-workspace kde-workspace
|
kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locke…
|
CWE-200
Information Exposure
|
CVE-2015-1308
|
2024-11-21 11:25 |
2015-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273957
|
- |
|
kde
|
plasma-workspace
|
plasma-workspace before 5.1.95 allows remote attackers to obtain passwords via a Trojan horse Look and Feel package.
|
CWE-284
Improper Access Control
|
CVE-2015-1307
|
2024-11-21 11:25 |
2015-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273958
|
- |
|
osticket
|
osticket
|
Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1347
|
2024-11-21 11:25 |
2015-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273959
|
- |
|
google chromium canonical
|
chrome chromium ubuntu_linux v8
|
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unkno…
|
NVD-CWE-noinfo
|
CVE-2015-1346
|
2024-11-21 11:25 |
2015-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273960
|
- |
|
sap
|
enterprise_resource_planning
|
The Dealer Portal in SAP ERP does not properly restrict access, which allows remote attackers to obtain sensitive information, gain privileges, and possibly have other unspecified impact via unknown …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1312
|
2024-11-21 11:25 |
2015-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|