|
273471
|
8.8 |
HIGH
Network
|
webgateinc
|
edvr_manager
|
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Connect, (2) ConnectEx, or (3) ConnectEx2 function in…
|
CWE-120
Classic Buffer Overflow
|
CVE-2015-2098
|
2024-11-21 11:26 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273472
|
8.8 |
HIGH
Network
|
freedesktop debian
|
xdg-utils debian_linux
|
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands…
|
CWE-77
Command Injection
|
CVE-2015-1877
|
2024-11-21 11:26 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273473
|
7.5 |
HIGH
Network
|
rust-lang
|
rust
|
In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe. The binary heap is left in an inconsistent state when the comparison of generic elements inside sift_up or sift_down_range …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-20001
|
2024-11-21 11:26 |
2021-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273474
|
7.2 |
HIGH
Network
|
huge-it
|
huge-it_slider
|
Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide paramet…
|
CWE-89
SQL Injection
|
CVE-2015-2062
|
2024-11-21 11:26 |
2020-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273475
|
7.5 |
HIGH
Network
|
jenkins
|
cloudbees
|
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document.
|
CWE-611
XXE
|
CVE-2015-1811
|
2024-11-21 11:26 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273476
|
7.5 |
HIGH
Network
|
jenkins
|
cloudbees
|
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.
|
CWE-611
XXE
|
CVE-2015-1809
|
2024-11-21 11:26 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273477
|
7.8 |
HIGH
Local
|
redhat
|
automatic_bug_reporting_tool
|
The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on a var_log_messages file.
|
CWE-59
Link Following
|
CVE-2015-1869
|
2024-11-21 11:26 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273478
|
6.5 |
MEDIUM
Network
|
tuxfamily
|
chrony
|
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (i…
|
NVD-CWE-Other
|
CVE-2015-1853
|
2024-11-21 11:26 |
2019-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273479
|
5.3 |
MEDIUM
Network
|
cabextract_project
|
cabextract
|
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character …
|
CWE-22
Path Traversal
|
CVE-2015-2060
|
2024-11-21 11:26 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273480
|
5.9 |
MEDIUM
Network
|
ruby-lang debian puppet
|
ruby trunk debian_linux puppet_enterprise puppet_agent
|
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attacker…
|
CWE-20
Improper Input Validation
|
CVE-2015-1855
|
2024-11-21 11:26 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|