|
269251
|
4.7 |
MEDIUM
Local
|
ibm
|
infosphere_information_server
|
IBM InfoSphere Information Server could allow a local user under special circumstances to execute commands during installation processes that could expose sensitive information.
|
CWE-200
Information Exposure
|
CVE-2015-7493
|
2024-11-21 11:36 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269252
|
4.4 |
MEDIUM
Local
|
ibm
|
websphere_extreme_scale
|
IBM WebSphere eXtreme Scale and the WebSphere DataPower XC10 Appliance allow some sensitive data to linger in memory instead of being overwritten which could allow a local user with administrator pri…
|
CWE-200
Information Exposure
|
CVE-2015-7418
|
2024-11-21 11:36 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269253
|
6.6 |
MEDIUM
Network
|
puppetlabs
|
mcollective-puppet-agent
|
The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --server argument.
|
CWE-254
7PK - Security Features
|
CVE-2015-7331
|
2024-11-21 11:36 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269254
|
5.4 |
MEDIUM
Network
|
fortinet
|
fortimanager_firmware fortianalyzer_firmware
|
Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x be…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7363
|
2024-11-21 11:36 |
2016-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269255
|
9.8 |
CRITICAL
Network
|
apple
|
airport_base_station_firmware
|
Apple AirPort Base Station Firmware before 7.6.7 and 7.7.x before 7.7.7 misparses DNS data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) vi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7029
|
2024-11-21 11:36 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269256
|
2.5 |
LOW
Local
|
ibm
|
websphere_mq
|
runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restrictions by leveraging authority for +connect and +dsp.
|
CWE-284
Improper Access Control
|
CVE-2015-7473
|
2024-11-21 11:36 |
2016-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269257
|
4.4 |
MEDIUM
Local
|
ibm
|
websphere_mq
|
IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords within MQ trace output by leveraging administrator privileges to execute the mqcert…
|
CWE-255 CWE-200
Credentials Management Information Exposure
|
CVE-2015-7462
|
2024-11-21 11:36 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269258
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortisandbox_firmware
|
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface (WebUI) in Fortinet FortiSandbox before 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) ser…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7360
|
2024-11-21 11:36 |
2016-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269259
|
7.5 |
HIGH
Network
|
debian gnome
|
debian_linux librsvg
|
librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document.
|
CWE-20
Improper Input Validation
|
CVE-2015-7558
|
2024-11-21 11:36 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269260
|
7.5 |
HIGH
Network
|
gnome
|
librsvg
|
The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elemen…
|
CWE-20
Improper Input Validation
|
CVE-2015-7557
|
2024-11-21 11:36 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|