|
270951
|
7.5 |
HIGH
Network
|
fedoraproject suse redhat debian canonical ntp
|
fedora manager_proxy linux_enterprise_debuginfo manager linux_enterprise_server openstack_cloud enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
|
CWE-20
Improper Input Validation
|
CVE-2015-5194
|
2024-11-21 11:32 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270952
|
8.1 |
HIGH
Network
|
theforeman
|
foreman
|
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-…
|
CWE-200
Information Exposure
|
CVE-2015-5152
|
2024-11-21 11:32 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270953
|
7.5 |
HIGH
Network
|
elasticsearch elastic
|
logstash
|
Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server.
|
CWE-200
Information Exposure
|
CVE-2015-5378
|
2024-11-21 11:32 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270954
|
7.5 |
HIGH
Network
|
canonical gnu
|
ubuntu_linux glibc
|
res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).
|
CWE-476
NULL Pointer Dereference
|
CVE-2015-5180
|
2024-11-21 11:32 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270955
|
8.1 |
HIGH
Network
|
cornelisnetworks
|
opa-ff opa-fm
|
Race conditions in opa-fm before 10.4.0.0.196 and opa-ff before 10.4.0.0.197.
|
CWE-362
Race Condition
|
CVE-2015-5232
|
2024-11-21 11:32 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270956
|
7.5 |
HIGH
Network
|
apache
|
cxf_fediz
|
Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2015-5175
|
2024-11-21 11:32 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270957
|
9.6 |
CRITICAL
Network
|
vmware debian
|
spring_framework debian_linux
|
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2015-5211
|
2024-11-21 11:32 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270958
|
7.5 |
HIGH
Network
|
teradata
|
teradata_express teradata_gateway
|
Teradata Gateway before 15.00.03.02-1 and 15.10.x before 15.10.00.01-1 and TD Express before 15.00.02.08_Sles10 and 15.00.02.08_Sles11 allow remote attackers to cause a denial of service (database cr…
|
CWE-20
Improper Input Validation
|
CVE-2015-5401
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270959
|
7.5 |
HIGH
Network
|
roundcube
|
roundcube_webmail webmail
|
Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.
|
CWE-200
Information Exposure
|
CVE-2015-5383
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270960
|
6.5 |
MEDIUM
Network
|
roundcube
|
roundcube_webmail webmail
|
program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.
|
CWE-200
Information Exposure
|
CVE-2015-5382
|
2024-11-21 11:32 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|