|
272581
|
7.5 |
HIGH
Network
|
accellion
|
file_transfer_appliance
|
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote attackers to read arbitrary files via a .. (d…
|
CWE-22
Path Traversal
|
CVE-2015-2856
|
2024-11-21 11:28 |
2017-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272582
|
7.5 |
HIGH
Network
|
tcpdump opensuse_project opensuse
|
tcpdump leap
|
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
|
CWE-20
Improper Input Validation
|
CVE-2015-3138
|
2024-11-21 11:28 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272583
|
4.7 |
MEDIUM
Local
|
openhpi
|
openhpi
|
openhpi/Makefile.am in OpenHPI before 3.6.0 uses world-writable permissions for /var/lib/openhpi directory, which allows local users, when quotas are not properly setup, to fill the filesystem hostin…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-3248
|
2024-11-21 11:28 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272584
|
6.5 |
MEDIUM
Network
|
uronode nodejs debian
|
uro_node node.js debian_linux
|
node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).
|
CWE-399
Resource Management Errors
|
CVE-2015-2927
|
2024-11-21 11:28 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272585
|
5.3 |
MEDIUM
Network
|
simple_ads_manager_project
|
simple_ads_manager
|
WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2015-2826
|
2024-11-21 11:28 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272586
|
7.0 |
HIGH
Local
|
ossec
|
ossec
|
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3222
|
2024-11-21 11:28 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272587
|
6.1 |
MEDIUM
Network
|
askbot
|
askbot
|
Cross-site scripting (XSS) vulnerability in askbot 0.7.51-4.el6.noarch.
|
CWE-79
Cross-site Scripting
|
CVE-2015-3169
|
2024-11-21 11:28 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272588
|
7.5 |
HIGH
Network
|
apache
|
directory_ldap_api
|
Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2015-3250
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272589
|
4.3 |
MEDIUM
Network
|
redhat
|
beaker
|
The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote authenticated users to modify power types and key types via navigating to $BEA…
|
CWE-284
Improper Access Control
|
CVE-2015-3163
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272590
|
5.4 |
MEDIUM
Network
|
beaker-project
|
beaker
|
Cross-site scripting (XSS) vulnerability in the edit comment dialog in bkr/server/widgets.py in Beaker 20.1 allows remote authenticated users to inject arbitrary web script or HTML via writing a craf…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3162
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|