|
270931
|
6.1 |
MEDIUM
Network
|
anchorcms
|
anchor_cms
|
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5060
|
2024-11-21 11:32 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270932
|
9.8 |
CRITICAL
Network
|
sefrengo
|
sefrengo
|
SQL injection vulnerability in Sefrengo before 1.6.5 beta2.
|
CWE-89
SQL Injection
|
CVE-2015-5052
|
2024-11-21 11:32 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270933
|
5.3 |
MEDIUM
Network
|
linux_audit_project
|
linux_audit
|
Audit before 2.4.4 in Linux does not sanitize escape characters in filenames.
|
CWE-20
Improper Input Validation
|
CVE-2015-5186
|
2024-11-21 11:32 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270934
|
7.5 |
HIGH
Network
|
apache
|
struts
|
Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vectors involving a top object.
|
CWE-20
Improper Input Validation
|
CVE-2015-5209
|
2024-11-21 11:32 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270935
|
5.9 |
MEDIUM
Network
|
redhat
|
enterprise_virtualization_manager
|
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a …
|
CWE-284
Improper Access Control
|
CVE-2015-5293
|
2024-11-21 11:32 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270936
|
5.3 |
MEDIUM
Network
|
fedoraproject debian ntp
|
fedora debian_linux ntp
|
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote config…
|
CWE-20
Improper Input Validation
|
CVE-2015-5146
|
2024-11-21 11:32 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270937
|
9.8 |
CRITICAL
Network
|
kernel
|
util-linux
|
The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks.
|
NVD-CWE-noinfo
|
CVE-2015-5224
|
2024-11-21 11:32 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270938
|
8.8 |
HIGH
Network
|
fedoraproject vmware
|
fedora spring_social
|
Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.
|
CWE-352
Origin Validation Error
|
CVE-2015-5258
|
2024-11-21 11:32 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270939
|
8.8 |
HIGH
Network
|
pulp_project
|
pulp
|
Pulp does not remove permissions for named objects upon deletion, which allows authenticated users to gain the privileges of a deleted object via creating an object with the same name.
|
CWE-275
Permission Issues
|
CVE-2015-5153
|
2024-11-21 11:32 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270940
|
8.8 |
HIGH
Network
|
django-cms
|
django_cms
|
Cross-site request forgery (CSRF) vulnerability in django CMS before 3.0.14, 3.1.x before 3.1.1 allows remote attackers to manipulate privileged users into performing unknown actions via unspecified …
|
CWE-352
Origin Validation Error
|
CVE-2015-5081
|
2024-11-21 11:32 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|