|
270871
|
6.5 |
MEDIUM
Network
|
jenkins
|
google_login
|
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps …
|
CWE-287
Improper Authentication
|
CVE-2015-5298
|
2024-11-21 11:32 |
2022-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270872
|
7.5 |
HIGH
Network
|
icedtea-web_project
|
icedtea-web
|
It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not h…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2015-5236
|
2024-11-21 11:32 |
2022-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270873
|
6.5 |
MEDIUM
Network
|
juniper
|
junos
|
Background For regular, unencrypted FTP traffic, the FTP ALG can inspect the unencrypted control channel and open related sessions for the FTP data channel. These related sessions (gates) are specifi…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2015-5361
|
2024-11-21 11:32 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270874
|
7.5 |
HIGH
Network
|
redhat
|
enterprise_virtualization_hypervisor enterprise_virtualization
|
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2015-5201
|
2024-11-21 11:32 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270875
|
6.1 |
MEDIUM
Network
|
ipsilon-project
|
ipsilon
|
The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly escape certain characters in a Python exception-message template, which makes it easier for remote attackers to cond…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5216
|
2024-11-21 11:32 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270876
|
6.1 |
MEDIUM
Network
|
ipsilon-project
|
ipsilon
|
The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not enable auto-escaping, which makes it easier for remote attac…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5215
|
2024-11-21 11:32 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270877
|
7.5 |
HIGH
Network
|
openbsd opensuse
|
libressl opensuse
|
Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 cert…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-5333
|
2024-11-21 11:32 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270878
|
9.8 |
CRITICAL
Network
|
openbsd opensuse
|
libressl opensuse
|
Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certi…
|
CWE-787
Out-of-bounds Write
|
CVE-2015-5334
|
2024-11-21 11:32 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270879
|
6.5 |
MEDIUM
Network
|
qemu fedoraproject canonical arista
|
qemu fedora ubuntu_linux eos
|
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors r…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2015-5278
|
2024-11-21 11:32 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270880
|
6.5 |
MEDIUM
Network
|
qemu fedoraproject canonical suse arista
|
qemu fedora ubuntu_linux linux_enterprise_server linux_enterprise_desktop linux_enterprise_debuginfo linux_enterprise_software_development_kit eos
|
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2015-5239
|
2024-11-21 11:32 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|