|
272591
|
4.8 |
MEDIUM
Network
|
beaker-project
|
beaker
|
The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals when producing JSON.
|
CWE-79
Cross-site Scripting
|
CVE-2015-3161
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272592
|
4.3 |
MEDIUM
Network
|
beaker-project
|
beaker
|
XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing e…
|
CWE-611
XXE
|
CVE-2015-3160
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272593
|
5.9 |
MEDIUM
Network
|
honda
|
moto_linc
|
Honda Moto LINC 1.6.1 does not verify SSL certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-2943
|
2024-11-21 11:28 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272594
|
5.5 |
MEDIUM
Local
|
php-fpm
|
php-fpm
|
php-fpm allows local users to write to or create arbitrary files via a symlink attack.
|
CWE-59
Link Following
|
CVE-2015-3211
|
2024-11-21 11:28 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272595
|
8.1 |
HIGH
Network
|
apple
|
pykerberos
|
The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other u…
|
CWE-287
Improper Authentication
|
CVE-2015-3206
|
2024-11-21 11:28 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272596
|
9.8 |
CRITICAL
Network
|
accellion
|
file_transfer_appliance
|
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.
|
CWE-77
Command Injection
|
CVE-2015-2857
|
2024-11-21 11:28 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272597
|
5.5 |
MEDIUM
Local
|
openstack
|
trove
|
The _write_config function in trove/guestagent/datastore/experimental/mongodb/service.py, reset_configuration function in trove/guestagent/datastore/experimental/postgresql/service/config.py, write_c…
|
CWE-59
Link Following
|
CVE-2015-3156
|
2024-11-21 11:28 |
2017-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272598
|
5.5 |
MEDIUM
Local
|
rsyslog
|
rsyslog
|
rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2015-3243
|
2024-11-21 11:28 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272599
|
5.5 |
MEDIUM
Local
|
sos_project
|
sos
|
sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.
|
CWE-200
Information Exposure
|
CVE-2015-3171
|
2024-11-21 11:28 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272600
|
5.5 |
MEDIUM
Local
|
redhat
|
enterprise_linux_desktop enterprise_linux_server_eus enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_aus enterprise_linux_hpc_…
|
The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.
|
CWE-59
Link Following
|
CVE-2015-3149
|
2024-11-21 11:28 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|