|
269191
|
9.8 |
CRITICAL
Network
|
puppet
|
puppetlabs-mysql
|
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host…
|
CWE-287
Improper Authentication
|
CVE-2015-7224
|
2024-11-21 11:36 |
2017-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269192
|
4.2 |
MEDIUM
Physics
|
seagate
|
st500lt015_firmware
|
Seagate ST500LT015 hard disk drives, when operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21, allow physically proximate attackers to bypass self-encrypting drive (SED) protectio…
|
CWE-254
7PK - Security Features
|
CVE-2015-7269
|
2024-11-21 11:36 |
2017-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269193
|
4.2 |
MEDIUM
Physics
|
samsung seagate
|
850_pro_firmware pm851_firmware st500lt015_firmware st500lt025_firmware
|
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Windows and operating in Opal mode on Lenovo ThinkPad T440s laptops with BIOS 2.32 or…
|
CWE-254
7PK - Security Features
|
CVE-2015-7268
|
2024-11-21 11:36 |
2017-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269194
|
4.2 |
MEDIUM
Physics
|
samsung seagate
|
850_pro_firmware pm851_firmware st500lt015_firmware st500lt025_firmware
|
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS…
|
CWE-254
7PK - Security Features
|
CVE-2015-7267
|
2024-11-21 11:36 |
2017-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269195
|
9.8 |
CRITICAL
Network
|
redhat
|
jboss_operations_network jboss_a-mq jboss_enterprise_application_platform jboss_bpm_suite jboss_enterprise_brms_platform openshift jboss_fuse subscription_asset_manager jboss_…
|
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2015-7501
|
2024-11-21 11:36 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269196
|
7.8 |
HIGH
Local
|
sos_project canonical redhat
|
sos ubuntu_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterprise_linux_server_eus
|
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by so…
|
CWE-59
Link Following
|
CVE-2015-7529
|
2024-11-21 11:36 |
2017-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269197
|
6.0 |
MEDIUM
Local
|
qemu
|
qemu
|
The MSI-X MMIO support in hw/pci/msix.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by leveragin…
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-7549
|
2024-11-21 11:36 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269198
|
8.8 |
HIGH
Local
|
qemu xen debian
|
qemu xen debian_linux
|
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via …
|
CWE-787
Out-of-bounds Write
|
CVE-2015-7504
|
2024-11-21 11:36 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269199
|
7.5 |
HIGH
Network
|
zend
|
zend_framework
|
Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.
|
CWE-320
Key Management Errors
|
CVE-2015-7503
|
2024-11-21 11:36 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269200
|
7.5 |
HIGH
Network
|
nodejs
|
node.js
|
Node.js 4.0.0, 4.1.0, and 4.1.1 allows remote attackers to cause a denial of service.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-7384
|
2024-11-21 11:36 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|