|
273451
|
- |
|
netcat
|
netcat
|
NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.
|
CWE-200
Information Exposure
|
CVE-2015-2214
|
2024-11-21 11:27 |
2015-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273452
|
- |
|
dlguard
|
dlguard
|
DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php.
|
CWE-200
Information Exposure
|
CVE-2015-2209
|
2024-11-21 11:27 |
2015-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273453
|
5.5 |
MEDIUM
Local
|
xaviershay-dm-rails_porject
|
xaviershay-dm-rails
|
The xaviershay-dm-rails gem 0.10.3.8 for Ruby allows local users to discover MySQL credentials by listing a process and its arguments.
|
NVD-CWE-noinfo
|
CVE-2015-2179
|
2024-11-21 11:26 |
2023-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273454
|
7.5 |
HIGH
Network
|
jhipster
|
jhipster
|
JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by br…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2015-20110
|
2024-11-21 11:26 |
2023-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273455
|
7.2 |
HIGH
Network
|
hp arubanetworks
|
airwave
|
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.
|
CWE-20
Improper Input Validation
|
CVE-2015-2202
|
2024-11-21 11:26 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273456
|
7.2 |
HIGH
Network
|
hp arubanetworks
|
airwave
|
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.
|
CWE-78
OS Command
|
CVE-2015-2201
|
2024-11-21 11:26 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273457
|
5.5 |
MEDIUM
Local
|
gnu
|
glibc
|
end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstra…
|
CWE-120
Classic Buffer Overflow
|
CVE-2015-20109
|
2024-11-21 11:26 |
2023-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273458
|
9.8 |
CRITICAL
Network
|
onelogin
|
ruby-saml
|
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
|
CWE-77
Command Injection
|
CVE-2015-20108
|
2024-11-21 11:26 |
2023-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273459
|
5.5 |
MEDIUM
Local
|
ibm suse redhat
|
java_sdk linux_enterprise_server linux_enterprise_software_development_kit enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation satellite enterprise_linu…
|
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores pl…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2015-1931
|
2024-11-21 11:26 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273460
|
6.5 |
MEDIUM
Network
|
imagely
|
nextgen_gallery
|
In nextgen-galery wordpress plugin before 2.0.77.3 there are two vulnerabilities which can allow an attacker to gain full access over the web application. The vulnerabilities lie in how the applicati…
|
CWE-352
Origin Validation Error
|
CVE-2015-1785
|
2024-11-21 11:26 |
2022-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|