|
273041
|
6.5 |
MEDIUM
Network
|
edx
|
open_edx
|
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attackers to discover passw…
|
CWE-200
Information Exposure
|
CVE-2015-2286
|
2024-11-21 11:27 |
2016-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273042
|
5.4 |
MEDIUM
Network
|
vmware
|
vrealize_automation
|
Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2344
|
2024-11-21 11:27 |
2016-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273043
|
- |
|
oracle pcre
|
linux pcre
|
PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have…
|
CWE-19
Data Processing Errors
|
CVE-2015-2328
|
2024-11-21 11:27 |
2015-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273044
|
- |
|
pcre
|
perl_compatible_regular_expression_library
|
PCRE before 8.36 mishandles the /(((a\2)|(a*)\g<-1>))*/ pattern and related patterns with certain internal recursive back references, which allows remote attackers to cause a denial of service (segme…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2327
|
2024-11-21 11:27 |
2015-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273045
|
- |
|
mit
|
kerberos_5
|
The iakerb_gss_export_sec_context function in lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) 1.14 pre-release 2015-09-14 improperly accesses a certain pointer, which allows remote authenticate…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2698
|
2024-11-21 11:27 |
2015-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273046
|
- |
|
microsoft
|
windows_server_2008 windows_server_2012 windows_rt windows_10 windows_8.1 windows_7 windows_rt_8.1 windows_vista windows_8
|
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allow lo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2478
|
2024-11-21 11:27 |
2015-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273047
|
- |
|
microsoft
|
internet_explorer
|
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulne…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2427
|
2024-11-21 11:27 |
2015-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273048
|
- |
|
microsoft
|
word onenote publisher powerpoint project_server infopath access excel project visio lync skype_for_business pinyin_ime office_2007_ime
|
Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2007 IME (Japanese) SP…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2503
|
2024-11-21 11:27 |
2015-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273049
|
- |
|
wordpress
|
wordpress
|
SQL injection vulnerability in the wp_untrash_post_comments function in wp-includes/post.php in WordPress before 4.2.4 allows remote attackers to execute arbitrary SQL commands via a comment that is …
|
CWE-89
SQL Injection
|
CVE-2015-2213
|
2024-11-21 11:27 |
2015-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273050
|
- |
|
mit oracle canonical debian opensuse suse
|
kerberos_5 solaris ubuntu_linux debian_linux leap opensuse linux_enterprise_server linux_enterprise_software_development_kit linux_enterprise_desktop
|
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) …
|
CWE-125
Out-of-bounds Read
|
CVE-2015-2697
|
2024-11-21 11:27 |
2015-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|