|
272451
|
- |
|
wppa.opajaap
|
wp-photo-album-plus
|
Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3647
|
2024-11-21 11:29 |
2015-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272452
|
- |
|
module-signature_project canonical
|
module-signature ubuntu_linux
|
Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan h…
|
NVD-CWE-Other
|
CVE-2015-3409
|
2024-11-21 11:29 |
2015-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272453
|
- |
|
module-signature_project canonical
|
module-signature ubuntu_linux
|
Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled when generating checksums from a signed manifest.
|
CWE-77
Command Injection
|
CVE-2015-3408
|
2024-11-21 11:29 |
2015-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272454
|
- |
|
canonical module-signature_project
|
ubuntu_linux module-signature
|
Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
|
CWE-284
Improper Access Control
|
CVE-2015-3407
|
2024-11-21 11:29 |
2015-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272455
|
- |
|
docker
|
docker
|
Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3631
|
2024-11-21 11:29 |
2015-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272456
|
- |
|
docker
|
docker
|
Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3630
|
2024-11-21 11:29 |
2015-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272457
|
7.8 |
HIGH
Local
|
docker opensuse
|
libcontainer opensuse
|
Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an imag…
|
CWE-59
Link Following
|
CVE-2015-3629
|
2024-11-21 11:29 |
2015-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272458
|
- |
|
docker
|
libcontainer docker
|
Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an …
|
CWE-59
Link Following
|
CVE-2015-3627
|
2024-11-21 11:29 |
2015-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272459
|
- |
|
oracle squid-cache fedoraproject
|
solaris linux squid fedora
|
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.50…
|
CWE-20
Improper Input Validation
|
CVE-2015-3455
|
2024-11-21 11:29 |
2015-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272460
|
- |
|
proftpd
|
proftpd
|
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
|
CWE-284
Improper Access Control
|
CVE-2015-3306
|
2024-11-21 11:29 |
2015-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|