|
267481
|
7.5 |
HIGH
Network
|
google
|
android
|
An issue was discovered on Samsung mobile devices with JBP(4.3) and KK(4.4.2) software. Because the READ_LOGS permission is mishandled, sensitive information is disclosed in a world-readable copy of …
|
CWE-200
Information Exposure
|
CVE-2015-9547
|
2024-11-21 11:40 |
2020-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267482
|
4.8 |
MEDIUM
Network
|
google
|
android
|
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker c…
|
CWE-22
Path Traversal
|
CVE-2015-9546
|
2024-11-21 11:40 |
2020-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267483
|
7.1 |
HIGH
Local
|
cross_domain_local_storage_project
|
cross_domain_local_storage
|
An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStorage.js does not implement any validation of the origin of web messages. Remote attackers who can e…
|
CWE-20
Improper Input Validation
|
CVE-2015-9545
|
2024-11-21 11:40 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267484
|
7.1 |
HIGH
Local
|
cross_domain_local_storage_project
|
cross_domain_local_storage
|
An issue was discovered in xdLocalStorage through 2.0.5. The receiveMessage() function in xdLocalStoragePostMessageApi.js does not implement any validation of the origin of web messages. Remote attac…
|
CWE-20
Improper Input Validation
|
CVE-2015-9544
|
2024-11-21 11:40 |
2020-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267485
|
7.5 |
HIGH
Network
|
freeradius debian canonical
|
pam_radius debian_linux ubuntu_linux
|
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could …
|
CWE-787
Out-of-bounds Write
|
CVE-2015-9542
|
2024-11-21 11:40 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267486
|
3.3 |
LOW
Local
|
openstack
|
nova
|
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs …
|
CWE-200
Information Exposure
|
CVE-2015-9543
|
2024-11-21 11:40 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267487
|
7.5 |
HIGH
Network
|
qt fedoraproject
|
qt fedora
|
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
|
CWE-776
XML Entity Expansion
|
CVE-2015-9541
|
2024-11-21 11:40 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267488
|
6.1 |
MEDIUM
Network
|
chamilo
|
chamilo_lms
|
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
|
CWE-601
Open Redirect
|
CVE-2015-9540
|
2024-11-21 11:40 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267489
|
6.1 |
MEDIUM
Network
|
fast_secure_contact_form_project
|
fast_secure_contact_form
|
The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9539
|
2024-11-21 11:40 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267490
|
6.5 |
MEDIUM
Network
|
imagely
|
nextgen_gallery
|
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
|
CWE-22
Path Traversal
|
CVE-2015-9538
|
2024-11-21 11:40 |
2019-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|