|
269331
|
9.8 |
CRITICAL
Network
|
libtiff
|
libtiff
|
The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field da…
|
CWE-254
7PK - Security Features
|
CVE-2015-7554
|
2024-11-21 11:36 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269332
|
3.7 |
LOW
Network
|
phusionpassenger
|
phusion_passenger
|
agent/Core/Controller/SendRequest.cpp in Phusion Passenger before 4.0.60 and 5.0.x before 5.0.22, when used in Apache integration mode or in standalone mode without a filtering proxy, allows remote a…
|
CWE-20
Improper Input Validation
|
CVE-2015-7519
|
2024-11-21 11:36 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269333
|
7.8 |
HIGH
Local
|
fortinet
|
forticlient
|
Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable and executable, allows local users to gain privileges via the helper/subroc set…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7362
|
2024-11-21 11:36 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269334
|
4.7 |
MEDIUM
Local
|
puppet
|
puppet_enterprise
|
Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permissions for the private key of the Certification Authority (CA) certificate during th…
|
CWE-200
Information Exposure
|
CVE-2015-7328
|
2024-11-21 11:36 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269335
|
4.7 |
MEDIUM
Local
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive cleartext web-services information by leveraging database access.
|
CWE-200
Information Exposure
|
CVE-2015-7438
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269336
|
5.5 |
MEDIUM
Local
|
ibm
|
sterling_b2b_integrator
|
Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-7437
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269337
|
2.5 |
LOW
Local
|
ibm
|
tivoli_common_reporting
|
IBM Tivoli Common Reporting (TCR) 2.1 before IF14, 2.1.1 before IF22, 2.1.1.2 before IF9, 3.1.0.0 through 3.1.2 as used in Cognos Business Intelligence before 10.2 IF16, and 3.1.2.1 as used in Cognos…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7436
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269338
|
2.5 |
LOW
Local
|
ibm
|
tivoli_common_reporting
|
IBM Tivoli Common Reporting (TCR) 2.1 before IF14, 2.1.1 before IF22, 2.1.1.2 before IF9, 3.1.0.0 through 3.1.2 as used in Cognos Business Intelligence before 10.2 IF16, and 3.1.2.1 as used in Cognos…
|
CWE-254
7PK - Security Features
|
CVE-2015-7435
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269339
|
4.3 |
MEDIUM
Network
|
ibm
|
maximo_for_transportation maximo_for_utilities maximo_asset_management smartcloud_control_desk maximo_for_life_sciences maximo_asset_management_essentials maximo_for_nuclear_power
|
IBM Maximo Asset Management 7.5 before 7.5.0.9 FP9 and 7.6 before 7.6.0.3 FP3 and Maximo Asset Management 7.5 before 7.5.0.9 FP9, 7.5.1, and 7.6 before 7.6.0.3 FP3 for SmartCloud Control Desk allow r…
|
CWE-200
Information Exposure
|
CVE-2015-7452
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269340
|
6.1 |
MEDIUM
Network
|
ibm
|
sterling_b2b_integrator
|
Cross-site scripting (XSS) vulnerability in Queue Watcher in IBM Sterling B2B Integrator 5.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7431
|
2024-11-21 11:36 |
2016-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|