|
269311
|
3.5 |
LOW
Network
|
openstack
|
nova
|
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read …
|
CWE-200
Information Exposure
|
CVE-2015-7548
|
2024-11-21 11:36 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269312
|
6.1 |
MEDIUM
Network
|
avm
|
fritz\!_os
|
Cross-site scripting (XSS) vulnerability in the Push-Service-Mails feature in AVM FRITZ!OS before 6.30 allows remote attackers to inject arbitrary web script or HTML via the display name in the FROM …
|
CWE-79
Cross-site Scripting
|
CVE-2015-7242
|
2024-11-21 11:36 |
2016-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269313
|
5.3 |
MEDIUM
Network
|
ibm
|
integration_bus websphere_message_broker
|
IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attackers to obtain sensitive information about the HTT…
|
CWE-200
Information Exposure
|
CVE-2015-7399
|
2024-11-21 11:36 |
2016-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269314
|
6.7 |
MEDIUM
Local
|
apple
|
mac_os_x
|
Untrusted search path vulnerability in Apple OS X before 10.11.1 allows local users to bypass intended Gatekeeper restrictions and gain privileges via a Trojan horse program that is loaded from an un…
|
NVD-CWE-Other
|
CVE-2015-7024
|
2024-11-21 11:36 |
2016-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269315
|
3.1 |
LOW
Network
|
ibm
|
jazz_reporting_service
|
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass int…
|
CWE-74
Injection
|
CVE-2015-7466
|
2024-11-21 11:36 |
2016-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269316
|
8.8 |
HIGH
Network
|
ibm
|
jazz_reporting_service
|
Cross-site request forgery (CSRF) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service (JRS) 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to hijack t…
|
CWE-352
Origin Validation Error
|
CVE-2015-7465
|
2024-11-21 11:36 |
2016-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269317
|
7.4 |
HIGH
Network
|
ibm
|
websphere_commerce
|
Multiple open redirect vulnerabilities in the Aurora starter store in IBM WebSphere Commerce 7.0 through Feature Pack 8 allow remote attackers to redirect users to arbitrary web sites and conduct phi…
|
NVD-CWE-Other
|
CVE-2015-7397
|
2024-11-21 11:36 |
2016-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269318
|
4.3 |
MEDIUM
Network
|
apple
|
tvos mac_os_x iphone_os
|
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML do…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7116
|
2024-11-21 11:36 |
2016-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269319
|
4.3 |
MEDIUM
Network
|
apple
|
iphone_os mac_os_x tvos
|
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML do…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7115
|
2024-11-21 11:36 |
2016-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269320
|
6.6 |
MEDIUM
Local
|
apple
|
quicktime
|
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerabili…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7117
|
2024-11-21 11:36 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|