|
270911
|
7.2 |
HIGH
Network
|
pulpproject
|
qpid
|
The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2015-5164
|
2024-11-21 11:32 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270912
|
8.1 |
HIGH
Network
|
theforeman
|
foreman
|
The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.
|
CWE-254
7PK - Security Features
|
CVE-2015-5246
|
2024-11-21 11:32 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270913
|
3.1 |
LOW
Network
|
wesnoth fedoraproject
|
battle_for_wesnoth fedora
|
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insens…
|
CWE-200
Information Exposure
|
CVE-2015-5070
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270914
|
4.3 |
MEDIUM
Network
|
wesnoth fedoraproject
|
battle_for_wesnoth fedora
|
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attack…
|
CWE-200
Information Exposure
|
CVE-2015-5069
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270915
|
6.5 |
MEDIUM
Network
|
linux
|
linux_kernel
|
Out-of-bounds memory read in the x509_decode_time function in x509_cert_parser.c in Linux kernels 4.3-rc1 and after.
|
CWE-125
Out-of-bounds Read
|
CVE-2015-5327
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270916
|
8.1 |
HIGH
Network
|
pulpproject
|
pulp
|
pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-5263
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270917
|
7.5 |
HIGH
Network
|
redhat
|
jboss_enterprise_web_server amq
|
Console: CORS headers set to allow all in Red Hat AMQ.
|
NVD-CWE-noinfo
|
CVE-2015-5184
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270918
|
7.5 |
HIGH
Network
|
redhat
|
jboss_enterprise_web_server jboss_a-mq amq
|
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
|
NVD-CWE-noinfo
|
CVE-2015-5183
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270919
|
8.8 |
HIGH
Network
|
redhat
|
amq
|
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
|
CWE-352
Origin Validation Error
|
CVE-2015-5182
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270920
|
5.4 |
MEDIUM
Network
|
redhat
|
jboss_a-mq
|
The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5181
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|