|
272341
|
5.4 |
MEDIUM
Network
|
redhat
|
jboss_a-mq
|
The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5181
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272342
|
6.1 |
MEDIUM
Network
|
apache
|
struts
|
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5169
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272343
|
6.1 |
MEDIUM
Network
|
theforeman
|
foreman
|
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5282
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272344
|
8.8 |
HIGH
Network
|
google
|
protobuf
|
protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2015-5237
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272345
|
9.8 |
CRITICAL
Network
|
freeipa
|
freeipa
|
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
|
CWE-200
Information Exposure
|
CVE-2015-5284
|
2024-11-21 11:32 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272346
|
8.8 |
HIGH
Network
|
debian alinto
|
debian_linux sogo
|
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
|
CWE-352
Origin Validation Error
|
CVE-2015-5395
|
2024-11-21 11:32 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272347
|
6.5 |
MEDIUM
Network
|
redhat
|
feedhenry_enterprise_mobile_application_platform
|
Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
|
CWE-20
Improper Input Validation
|
CVE-2015-5248
|
2024-11-21 11:32 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272348
|
7.5 |
HIGH
Network
|
freeipa
|
freeipa
|
FreeIPA might display user data improperly via vectors involving non-printable characters.
|
CWE-20
Improper Input Validation
|
CVE-2015-5179
|
2024-11-21 11:32 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272349
|
9.8 |
CRITICAL
Network
|
apache
|
traffic_server
|
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5168.
|
NVD-CWE-noinfo
|
CVE-2015-5206
|
2024-11-21 11:32 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272350
|
9.8 |
CRITICAL
Network
|
apache
|
traffic_server
|
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206.
|
NVD-CWE-noinfo
|
CVE-2015-5168
|
2024-11-21 11:32 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|