|
273931
|
8.8 |
HIGH
Network
|
google
|
protobuf
|
protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2015-5237
|
2024-11-21 11:32 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273932
|
9.8 |
CRITICAL
Network
|
freeipa
|
freeipa
|
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
|
CWE-200
Information Exposure
|
CVE-2015-5284
|
2024-11-21 11:32 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273933
|
8.8 |
HIGH
Network
|
debian alinto
|
debian_linux sogo
|
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
|
CWE-352
Origin Validation Error
|
CVE-2015-5395
|
2024-11-21 11:32 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273934
|
6.5 |
MEDIUM
Network
|
redhat
|
feedhenry_enterprise_mobile_application_platform
|
Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
|
CWE-20
Improper Input Validation
|
CVE-2015-5248
|
2024-11-21 11:32 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273935
|
7.5 |
HIGH
Network
|
freeipa
|
freeipa
|
FreeIPA might display user data improperly via vectors involving non-printable characters.
|
CWE-20
Improper Input Validation
|
CVE-2015-5179
|
2024-11-21 11:32 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273936
|
9.8 |
CRITICAL
Network
|
apache
|
traffic_server
|
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5168.
|
NVD-CWE-noinfo
|
CVE-2015-5206
|
2024-11-21 11:32 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273937
|
9.8 |
CRITICAL
Network
|
apache
|
traffic_server
|
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206.
|
NVD-CWE-noinfo
|
CVE-2015-5168
|
2024-11-21 11:32 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273938
|
6.1 |
MEDIUM
Network
|
ellucian
|
banner_student
|
Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL i…
|
CWE-601
Open Redirect
|
CVE-2015-5054
|
2024-11-21 11:32 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273939
|
6.1 |
MEDIUM
Network
|
anchorcms
|
anchor_cms
|
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5060
|
2024-11-21 11:32 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273940
|
9.8 |
CRITICAL
Network
|
sefrengo
|
sefrengo
|
SQL injection vulnerability in Sefrengo before 1.6.5 beta2.
|
CWE-89
SQL Injection
|
CVE-2015-5052
|
2024-11-21 11:32 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|