|
277071
|
- |
|
redhat
|
openstack
|
The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary she…
|
CWE-255
Credentials Management
|
CVE-2015-1842
|
2024-11-21 11:26 |
2015-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277072
|
- |
|
ntp
|
ntp
|
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 3.x and 4.x before 4.2.8p2 performs state-variable updates upon receiving certain invalid packets, which makes it easie…
|
CWE-17
Code
|
CVE-2015-1799
|
2024-11-21 11:26 |
2015-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277073
|
- |
|
ntp
|
ntp
|
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-…
|
CWE-17
Code
|
CVE-2015-1798
|
2024-11-21 11:26 |
2015-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277074
|
- |
|
apache
|
flex
|
Cross-site scripting (XSS) vulnerability in asdoc/templates/index.html in Apache Flex before 4.14.1 allows remote attackers to inject arbitrary web script or HTML by providing a crafted URI to JavaSc…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1773
|
2024-11-21 11:26 |
2015-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277075
|
- |
|
ericsson
|
drutt_mobile_service_delivery_platform
|
Open redirect vulnerability in the 3PI Manager in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to redirect users to arbitrary web sites and conduct phish…
|
NVD-CWE-Other
|
CVE-2015-2167
|
2024-11-21 11:26 |
2015-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277076
|
- |
|
ericsson
|
drutt_mobile_service_delivery_platform
|
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot en…
|
CWE-22
Path Traversal
|
CVE-2015-2166
|
2024-11-21 11:26 |
2015-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277077
|
- |
|
redhat
|
docker
|
The Red Hat docker package before 1.5.0-28, when using the --add-registry option, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to condu…
|
CWE-20
Improper Input Validation
|
CVE-2015-1843
|
2024-11-21 11:26 |
2015-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277078
|
- |
|
ibm
|
websphere_datapower_xc10_appliance_firmware
|
The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obtain sensitive information or modify data, via unsp…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1893
|
2024-11-21 11:26 |
2015-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277079
|
- |
|
ibm
|
general_parallel_file_system
|
/usr/lpp/mmfs/bin/gpfs.snap in IBM General Parallel File System (GPFS) 4.1 before 4.1.0.7 produces an archive potentially containing cleartext keys, and lacks a warning about reviewing this archive t…
|
CWE-200
Information Exposure
|
CVE-2015-1890
|
2024-11-21 11:26 |
2015-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277080
|
- |
|
ericsson
|
drutt_mobile_service_delivery_platform
|
Multiple cross-site scripting (XSS) vulnerabilities in the Report Viewer in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4.x, 5.x, and 6.x allow remote attackers to inject arbitrary web scr…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2165
|
2024-11-21 11:26 |
2015-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|