|
273521
|
7.5 |
HIGH
Network
|
fedoraproject entrouvert
|
fedora lasso
|
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-1783
|
2024-11-21 11:26 |
2017-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273522
|
9.8 |
CRITICAL
Network
|
rest-client_project
|
rest-client
|
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a respon…
|
CWE-384
Session Fixation
|
CVE-2015-1820
|
2024-11-21 11:26 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273523
|
7.5 |
HIGH
Network
|
appserver
|
appserver
|
Directory traversal vulnerability in the web request/response interface in Appserver before 1.0.3 allows remote attackers to read normally inaccessible files via a .. (dot dot) in a crafted URL.
|
CWE-22
Path Traversal
|
CVE-2015-1847
|
2024-11-21 11:26 |
2017-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273524
|
7.8 |
HIGH
Local
|
redhat
|
gluster_storage
|
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1795
|
2024-11-21 11:26 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273525
|
9.8 |
CRITICAL
Network
|
opendaylight
|
opendaylight
|
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.
|
CWE-287
Improper Authentication
|
CVE-2015-1778
|
2024-11-21 11:26 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273526
|
5.5 |
MEDIUM
Local
|
redhat
|
automatic_bug_reporting_tool
|
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information fr…
|
CWE-200
Information Exposure
|
CVE-2015-1870
|
2024-11-21 11:26 |
2017-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273527
|
8.8 |
HIGH
Network
|
zend
|
zend_framework
|
Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.
|
CWE-352
Origin Validation Error
|
CVE-2015-1786
|
2024-11-21 11:26 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273528
|
6.5 |
MEDIUM
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cf-release
|
A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects cf-release versions prior to v208 and Pivotal Cloud Foundry Elastic Runtime versions prior t…
|
CWE-22
Path Traversal
|
CVE-2015-1834
|
2024-11-21 11:26 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273529
|
5.3 |
MEDIUM
Local
|
saltstack fedoraproject
|
salt fedora
|
modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
|
CWE-19
Data Processing Errors
|
CVE-2015-1839
|
2024-11-21 11:26 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273530
|
5.3 |
MEDIUM
Local
|
saltstack fedoraproject
|
salt fedora
|
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
|
CWE-19
Data Processing Errors
|
CVE-2015-1838
|
2024-11-21 11:26 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|