|
272631
|
5.9 |
MEDIUM
Network
|
erlang oracle opensuse
|
erlang\/otp solaris opensuse
|
Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle …
|
CWE-200
Information Exposure
|
CVE-2015-2774
|
2024-11-21 11:28 |
2016-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272632
|
5.9 |
MEDIUM
Network
|
oracle openssl
|
tuxedo exalogic_infrastructure peoplesoft_enterprise_peopletools openssl oss_support_tools vm_virtualbox
|
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection…
|
CWE-310 CWE-200
Cryptographic Issues Information Exposure
|
CVE-2015-3197
|
2024-11-21 11:28 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272633
|
9.8 |
CRITICAL
Network
|
apache
|
cloudstack
|
Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.
|
CWE-255
Credentials Management
|
CVE-2015-3252
|
2024-11-21 11:28 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272634
|
4.9 |
MEDIUM
Network
|
apache
|
cloudstack
|
Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API ca…
|
CWE-200
Information Exposure
|
CVE-2015-3251
|
2024-11-21 11:28 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272635
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, which allows remote attackers to cause a denial of ser…
|
CWE-20
Improper Input Validation
|
CVE-2015-3182
|
2024-11-21 11:28 |
2016-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272636
|
6.1 |
MEDIUM
Network
|
orientdb
|
orientdb
|
The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct …
|
CWE-20
Improper Input Validation
|
CVE-2015-2918
|
2024-11-21 11:28 |
2015-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272637
|
5.9 |
MEDIUM
Network
|
orientdb
|
orientdb
|
server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class…
|
CWE-200
Information Exposure
|
CVE-2015-2913
|
2024-11-21 11:28 |
2015-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272638
|
8.8 |
HIGH
Network
|
orientdb
|
orientdb
|
The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values, which allows remote attackers to condu…
|
CWE-352
Origin Validation Error
|
CVE-2015-2912
|
2024-11-21 11:28 |
2015-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272639
|
5.3 |
MEDIUM
Network
|
idera
|
uptime_infrastructure_monitor
|
The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, process, and event-log information via a command.
|
CWE-200
Information Exposure
|
CVE-2015-2896
|
2024-11-21 11:28 |
2015-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272640
|
7.3 |
HIGH
Network
|
idera
|
uptime_infrastructure_monitor
|
Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via long command input.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2895
|
2024-11-21 11:28 |
2015-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|