|
273891
|
5.5 |
MEDIUM
Local
|
gnupg debian
|
gnupg debian_linux
|
The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a crafted keyring file.
|
CWE-416
Use After Free
|
CVE-2015-1606
|
2024-11-21 11:25 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273892
|
5.3 |
MEDIUM
Network
|
canonical
|
ubuntu_linux
|
All versions of unity-scope-gdrive logs search terms to syslog.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2015-1343
|
2024-11-21 11:25 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273893
|
7.8 |
HIGH
Local
|
canonical
|
ubuntu_linux apport
|
Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1341
|
2024-11-21 11:25 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273894
|
8.1 |
HIGH
Network
|
linuxcontainers
|
lxd
|
LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause a…
|
CWE-362
Race Condition
|
CVE-2015-1340
|
2024-11-21 11:25 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273895
|
7.8 |
HIGH
Local
|
canonical
|
ubuntu_linux
|
Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transf…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1327
|
2024-11-21 11:25 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273896
|
8.8 |
HIGH
Network
|
python-dbusmock_project
|
python-dbusmock
|
python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method could be tricked into executing malicious code if an attacker supplies a .pyc file.
|
CWE-20
Improper Input Validation
|
CVE-2015-1326
|
2024-11-21 11:25 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273897
|
9.8 |
CRITICAL
Network
|
canonical
|
metal_as_a_service
|
The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface. This issue affects Ubuntu MAAS versions prior to 1.9.2.
|
CWE-255
Credentials Management
|
CVE-2015-1320
|
2024-11-21 11:25 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273898
|
7.5 |
HIGH
Network
|
canonical
|
juju
|
Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.
|
CWE-320
Key Management Errors
|
CVE-2015-1316
|
2024-11-21 11:25 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273899
|
7.5 |
HIGH
Network
|
icewarp
|
mail_server
|
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/d…
|
CWE-22
Path Traversal
|
CVE-2015-1503
|
2024-11-21 11:25 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273900
|
7.8 |
HIGH
Local
|
freebsd
|
freebsd
|
The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1 before 10.2-RC1-p2, and 0.2-RC2 before 10.2-RC2-p…
|
CWE-200
Information Exposure
|
CVE-2015-1418
|
2024-11-21 11:25 |
2018-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|