|
273471
|
9.8 |
CRITICAL
Network
|
freeipa
|
freeipa
|
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
|
CWE-200
Information Exposure
|
CVE-2015-5284
|
2024-11-21 11:32 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273472
|
8.8 |
HIGH
Network
|
debian alinto
|
debian_linux sogo
|
Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.
|
CWE-352
Origin Validation Error
|
CVE-2015-5395
|
2024-11-21 11:32 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273473
|
6.5 |
MEDIUM
Network
|
redhat
|
feedhenry_enterprise_mobile_application_platform
|
Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.
|
CWE-20
Improper Input Validation
|
CVE-2015-5248
|
2024-11-21 11:32 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273474
|
7.5 |
HIGH
Network
|
freeipa
|
freeipa
|
FreeIPA might display user data improperly via vectors involving non-printable characters.
|
CWE-20
Improper Input Validation
|
CVE-2015-5179
|
2024-11-21 11:32 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273475
|
9.8 |
CRITICAL
Network
|
apache
|
traffic_server
|
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5168.
|
NVD-CWE-noinfo
|
CVE-2015-5206
|
2024-11-21 11:32 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273476
|
9.8 |
CRITICAL
Network
|
apache
|
traffic_server
|
Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206.
|
NVD-CWE-noinfo
|
CVE-2015-5168
|
2024-11-21 11:32 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273477
|
6.1 |
MEDIUM
Network
|
ellucian
|
banner_student
|
Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL i…
|
CWE-601
Open Redirect
|
CVE-2015-5054
|
2024-11-21 11:32 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273478
|
6.1 |
MEDIUM
Network
|
anchorcms
|
anchor_cms
|
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5060
|
2024-11-21 11:32 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273479
|
9.8 |
CRITICAL
Network
|
sefrengo
|
sefrengo
|
SQL injection vulnerability in Sefrengo before 1.6.5 beta2.
|
CWE-89
SQL Injection
|
CVE-2015-5052
|
2024-11-21 11:32 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273480
|
5.3 |
MEDIUM
Network
|
linux_audit_project
|
linux_audit
|
Audit before 2.4.4 in Linux does not sanitize escape characters in filenames.
|
CWE-20
Improper Input Validation
|
CVE-2015-5186
|
2024-11-21 11:32 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|