|
273511
|
6.5 |
MEDIUM
Network
|
qemu fedoraproject arista
|
qemu fedora eos
|
Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control …
|
CWE-120
Classic Buffer Overflow
|
CVE-2015-5745
|
2024-11-21 11:33 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273512
|
5.4 |
MEDIUM
Network
|
plot
|
plotly
|
Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via a post.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5484
|
2024-11-21 11:33 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273513
|
7.8 |
HIGH
Local
|
sis
|
xgi_vga_display_manager
|
Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.1090 allows local users to gain privileges via a crafted 0x96002404 IOCTL call.
|
CWE-269
Improper Privilege Management
|
CVE-2015-5466
|
2024-11-21 11:33 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273514
|
6.5 |
MEDIUM
Network
|
zenphoto
|
zenphoto
|
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of servi…
|
CWE-352
Origin Validation Error
|
CVE-2015-5595
|
2024-11-21 11:33 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273515
|
6.1 |
MEDIUM
Network
|
zenphoto
|
zenphoto
|
The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scripting (XSS) attack by wrapping a payload in "<<sc…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5593
|
2024-11-21 11:33 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273516
|
6.1 |
MEDIUM
Network
|
zenphoto
|
zenphoto
|
Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5592
|
2024-11-21 11:33 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273517
|
7.2 |
HIGH
Network
|
zenphoto
|
zenphoto
|
SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.
|
CWE-89
SQL Injection
|
CVE-2015-5591
|
2024-11-21 11:33 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273518
|
6.5 |
MEDIUM
Network
|
openstack redhat debian
|
designate enterprise_linux_openstack_platform debian_linux
|
Designate does not enforce the DNS protocol limit concerning record set sizes
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2015-5694
|
2024-11-21 11:33 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273519
|
8.8 |
HIGH
Network
|
edx
|
edx-platform
|
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-5601
|
2024-11-21 11:33 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273520
|
6.1 |
MEDIUM
Network
|
axiomsl
|
axiom
|
AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dashboard features.
|
CWE-74
Injection
|
CVE-2015-5462
|
2024-11-21 11:33 |
2019-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|