|
273481
|
6.5 |
MEDIUM
Network
|
redhat
|
virtualization ovirt-engine
|
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
|
CWE-863
Incorrect Authorization
|
CVE-2015-1780
|
2024-11-21 11:26 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273482
|
5.3 |
MEDIUM
Network
|
linuxfoundation
|
opendaylight
|
The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions.
|
CWE-200
Information Exposure
|
CVE-2015-1857
|
2024-11-21 11:26 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273483
|
5.4 |
MEDIUM
Network
|
ibm
|
security_appscan
|
Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Fo…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1952
|
2024-11-21 11:26 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273484
|
5.9 |
MEDIUM
Network
|
redhat
|
rhn-client-tools
|
rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not properly validate hostnames in X.509 certificates from…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-1777
|
2024-11-21 11:26 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273485
|
5.3 |
MEDIUM
Network
|
ibm
|
websphere_mq
|
IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-middle attack, related to duplication of message data…
|
CWE-200
Information Exposure
|
CVE-2015-1957
|
2024-11-21 11:26 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273486
|
7.8 |
HIGH
Local
|
ibm
|
tivoli_directory_server
|
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before i…
|
CWE-74
Injection
|
CVE-2015-1975
|
2024-11-21 11:26 |
2018-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273487
|
9.8 |
CRITICAL
Network
|
myscript
|
myscript
|
The MyScript SDK before 1.3 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer t…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2015-2020
|
2024-11-21 11:26 |
2018-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273488
|
8.8 |
HIGH
Network
|
ibm
|
qradar_security_information_and_event_manager
|
Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before 7.2.5 Patch 4 allows remote attackers to hijack th…
|
CWE-352
Origin Validation Error
|
CVE-2015-2009
|
2024-11-21 11:26 |
2018-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273489
|
9.8 |
CRITICAL
Network
|
gracenote
|
gnsdk
|
The GraceNote GNSDK SDK before SVN Changeset 1.1.7 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attack…
|
CWE-118
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2004
|
2024-11-21 11:26 |
2018-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273490
|
9.8 |
CRITICAL
Network
|
pjsip
|
pjsua2_sdk
|
The PJSIP PJSUA2 SDK before SVN Changeset 51322 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-…
|
CWE-118
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2003
|
2024-11-21 11:26 |
2018-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|