|
277331
|
- |
|
iodata
|
wn-g54\/r2_firmware
|
I-O DATA DEVICE WN-G54/R2 routers with firmware before 1.03 and NP-BBRS routers allow remote attackers to cause a denial of service (SSDP reflection) via UPnP requests.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2984
|
2024-11-21 11:28 |
2015-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277332
|
- |
|
debian openstack oracle
|
debian_linux horizon solaris
|
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015.1.x before 2015.1.1 allows remote attackers to inject arbi…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3219
|
2024-11-21 11:28 |
2015-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277333
|
- |
|
theforeman
|
foreman
|
Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3235
|
2024-11-21 11:28 |
2015-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277334
|
- |
|
theforeman
|
foreman
|
Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission wi…
|
CWE-284
Improper Access Control
|
CVE-2015-3155
|
2024-11-21 11:28 |
2015-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277335
|
- |
|
clutter_project
|
clutter
|
The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via certain (1) mouse or (2) touch gestures.
|
CWE-284
Improper Access Control
|
CVE-2015-3213
|
2024-11-21 11:28 |
2015-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277336
|
- |
|
apache apple
|
subversion xcode
|
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive pa…
|
CWE-200
Information Exposure
|
CVE-2015-3187
|
2024-11-21 11:28 |
2015-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277337
|
- |
|
apple apache
|
xcode subversion
|
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read…
|
CWE-200
Information Exposure
|
CVE-2015-3184
|
2024-11-21 11:28 |
2015-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277338
|
- |
|
redhat
|
libuser
|
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (incon…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3246
|
2024-11-21 11:28 |
2015-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277339
|
- |
|
redhat
|
libuser
|
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, allows local users to cause a de…
|
CWE-20
Improper Input Validation
|
CVE-2015-3245
|
2024-11-21 11:28 |
2015-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277340
|
- |
|
artifex
|
afpl_ghostscript
|
Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier allows remote attackers to cause a denial of service (crash) via a crafted Postscript (ps) file…
|
CWE-189
Numeric Errors
|
CVE-2015-3228
|
2024-11-21 11:28 |
2015-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|