|
280891
|
7.8 |
HIGH
Local
|
redhat
|
automatic_bug_reporting_tool
|
The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on a var_log_messages file.
|
CWE-59
Link Following
|
CVE-2015-1869
|
2024-11-21 11:26 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280892
|
6.5 |
MEDIUM
Network
|
tuxfamily
|
chrony
|
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (i…
|
NVD-CWE-Other
|
CVE-2015-1853
|
2024-11-21 11:26 |
2019-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280893
|
5.3 |
MEDIUM
Network
|
cabextract_project
|
cabextract
|
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character …
|
CWE-22
Path Traversal
|
CVE-2015-2060
|
2024-11-21 11:26 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280894
|
5.9 |
MEDIUM
Network
|
ruby-lang debian puppet
|
ruby trunk debian_linux puppet_enterprise puppet_agent
|
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attacker…
|
CWE-20
Improper Input Validation
|
CVE-2015-1855
|
2024-11-21 11:26 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280895
|
6.5 |
MEDIUM
Network
|
redhat
|
virtualization ovirt-engine
|
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
|
CWE-863
Incorrect Authorization
|
CVE-2015-1780
|
2024-11-21 11:26 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280896
|
5.3 |
MEDIUM
Network
|
linuxfoundation
|
opendaylight
|
The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions.
|
CWE-200
Information Exposure
|
CVE-2015-1857
|
2024-11-21 11:26 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280897
|
5.4 |
MEDIUM
Network
|
ibm
|
security_appscan
|
Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Fo…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1952
|
2024-11-21 11:26 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280898
|
5.9 |
MEDIUM
Network
|
redhat
|
rhn-client-tools
|
rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not properly validate hostnames in X.509 certificates from…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-1777
|
2024-11-21 11:26 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280899
|
5.3 |
MEDIUM
Network
|
ibm
|
websphere_mq
|
IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-middle attack, related to duplication of message data…
|
CWE-200
Information Exposure
|
CVE-2015-1957
|
2024-11-21 11:26 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280900
|
7.8 |
HIGH
Local
|
ibm
|
tivoli_directory_server
|
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before i…
|
CWE-74
Injection
|
CVE-2015-1975
|
2024-11-21 11:26 |
2018-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|