|
274181
|
7.8 |
HIGH
Local
|
redhat
|
gluster_storage
|
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1795
|
2024-11-21 11:26 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274182
|
9.8 |
CRITICAL
Network
|
opendaylight
|
opendaylight
|
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.
|
CWE-287
Improper Authentication
|
CVE-2015-1778
|
2024-11-21 11:26 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274183
|
5.5 |
MEDIUM
Local
|
redhat
|
automatic_bug_reporting_tool
|
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information fr…
|
CWE-200
Information Exposure
|
CVE-2015-1870
|
2024-11-21 11:26 |
2017-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274184
|
8.8 |
HIGH
Network
|
zend
|
zend_framework
|
Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.
|
CWE-352
Origin Validation Error
|
CVE-2015-1786
|
2024-11-21 11:26 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274185
|
6.5 |
MEDIUM
Network
|
pivotal_software cloudfoundry
|
cloud_foundry_elastic_runtime cf-release
|
A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects cf-release versions prior to v208 and Pivotal Cloud Foundry Elastic Runtime versions prior t…
|
CWE-22
Path Traversal
|
CVE-2015-1834
|
2024-11-21 11:26 |
2017-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274186
|
5.3 |
MEDIUM
Local
|
saltstack fedoraproject
|
salt fedora
|
modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
|
CWE-19
Data Processing Errors
|
CVE-2015-1839
|
2024-11-21 11:26 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274187
|
5.3 |
MEDIUM
Local
|
saltstack fedoraproject
|
salt fedora
|
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
|
CWE-19
Data Processing Errors
|
CVE-2015-1838
|
2024-11-21 11:26 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274188
|
5.5 |
MEDIUM
Local
|
ibm
|
security_directory_server tivoli_directory_server
|
IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash.
|
CWE-284
Improper Access Control
|
CVE-2015-1976
|
2024-11-21 11:26 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274189
|
8.8 |
HIGH
Network
|
roundcube
|
webmail
|
Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via the (1) password or (2) username.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2181
|
2024-11-21 11:26 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274190
|
8.8 |
HIGH
Network
|
roundcube
|
webmail
|
The DBMail driver in the Password plugin in Roundcube before 1.1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the password.
|
CWE-74
Injection
|
CVE-2015-2180
|
2024-11-21 11:26 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|