|
271081
|
- |
|
redhat jenkins
|
openshift jenkins
|
The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to the page…
|
CWE-200
Information Exposure
|
CVE-2015-5321
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271082
|
- |
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive informatio…
|
CWE-200
Information Exposure
|
CVE-2015-5320
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271083
|
- |
|
redhat jenkins
|
openshift jenkins
|
XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to read arbitrary files via a crafted job configuration th…
|
NVD-CWE-Other
|
CVE-2015-5319
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271084
|
- |
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which makes it easier for remote attackers to bypass the CSRF protection mechanism via …
|
CWE-352
Origin Validation Error
|
CVE-2015-5318
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271085
|
- |
|
openstack
|
ironic_inspector
|
OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by trigge…
|
CWE-254
7PK - Security Features
|
CVE-2015-5306
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271086
|
- |
|
redhat
|
gluster_storage
|
OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a cra…
|
CWE-94
Code Injection
|
CVE-2015-5242
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271087
|
- |
|
redhat
|
enterprise_linux
|
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5281
|
2024-11-21 11:32 |
2015-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271088
|
- |
|
nvidia
|
gpu_driver
|
The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict acc…
|
CWE-284
Improper Access Control
|
CVE-2015-5053
|
2024-11-21 11:32 |
2015-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271089
|
- |
|
apache
|
cordova
|
Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended access…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5256
|
2024-11-21 11:32 |
2015-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271090
|
- |
|
hp adobe
|
xp7_command_view_advanced_edition xp_p9000_command_view_advanced_edition coldfusion livecycle_data_services
|
Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x be…
|
CWE-20
Improper Input Validation
|
CVE-2015-5255
|
2024-11-21 11:32 |
2015-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|