|
274351
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows remote attackers to cause a denial of service (CPU consumption) via a long password.
|
CWE-399
Resource Management Errors
|
CVE-2015-2936
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274352
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style el…
|
CWE-200
Information Exposure
|
CVE-2015-2935
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274353
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 does not properly handle when the Zend interpreter xml_parse function does not expand entities, which allows remote attackers to…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2934
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274354
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in the Html class in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2933
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274355
|
- |
|
mediawiki
|
mediawiki
|
Incomplete blacklist vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an animated href XLink …
|
CWE-79
Cross-site Scripting
|
CVE-2015-2932
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274356
|
- |
|
mediawiki
|
mediawiki
|
Incomplete blacklist vulnerability in includes/upload/UploadBase.php in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script o…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2931
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274357
|
- |
|
bittorrent
|
sync
|
BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link.
|
CWE-77
Command Injection
|
CVE-2015-2846
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274358
|
- |
|
redhat canonical debian gnu
|
enterprise_linux ubuntu_linux debian_linux mailman
|
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
|
CWE-22
Path Traversal
|
CVE-2015-2775
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274359
|
- |
|
apple
|
xcode
|
Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way that triggers stack storage for stack cookie pointers, which might allow context-dependent attackers …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3027
|
2024-11-21 11:28 |
2015-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274360
|
- |
|
digium
|
asterisk certified_asterisk
|
Asterisk Open Source 1.8 before 1.8.32.3, 11.x before 11.17.1, 12.x before 12.8.2, and 13.x before 13.3.2 and Certified Asterisk 1.8.28 before 1.8.28-cert5, 11.6 before 11.6-cert11, and 13.1 before 1…
|
CWE-310
Cryptographic Issues
|
CVE-2015-3008
|
2024-11-21 11:28 |
2015-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|