|
212301
|
- |
|
libpng fedoraproject suse opensuse debian redhat oracle apple canonical
|
libpng fedora linux_enterprise_desktop linux_enterprise_server leap opensuse debian_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation<…
|
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x …
|
CWE-120
Classic Buffer Overflow
|
CVE-2015-8126
|
2024-11-21 11:38 |
2015-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212302
|
- |
|
symantec
|
endpoint_protection
|
Untrusted search path vulnerability in the client in Symantec Endpoint Protection (SEP) 12.1 before 12.1-RU6-MP3 allows local users to gain privileges via a Trojan horse DLL in a client install packa…
|
NVD-CWE-Other
|
CVE-2015-8113
|
2024-11-21 11:38 |
2015-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212303
|
- |
|
opensuse roundcube
|
opensuse webmail
|
Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8105
|
2024-11-21 11:38 |
2015-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212304
|
- |
|
net-snmp
|
net-snmp
|
The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf, which allows local users to obtain sensitive community information by reading this file.
|
CWE-200
Information Exposure
|
CVE-2015-8100
|
2024-11-21 11:38 |
2015-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212305
|
- |
|
google
|
picasa
|
Integer overflow in Google Picasa 3.9.140 Build 239 and Build 248 allows remote attackers to execute arbitrary code via unspecified vectors related to "phase one 0x412 tag," which triggers a heap-bas…
|
CWE-119 CWE-189
Incorrect Access of Indexable Resource ('Range Error') Numeric Errors
|
CVE-2015-8096
|
2024-11-21 11:38 |
2015-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212306
|
- |
|
monster_menus_module_project
|
monster_menus
|
The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote attackers to obtain sensitive information via an …
|
CWE-200
Information Exposure
|
CVE-2015-8095
|
2024-11-21 11:38 |
2015-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212307
|
9.8 |
CRITICAL
Network
|
eclipse
|
hudson
|
Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks.
|
CWE-611
XXE
|
CVE-2015-8031
|
2024-11-21 11:37 |
2022-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212308
|
5.5 |
MEDIUM
Local
|
sap
|
mobile_platform
|
SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the DataVault, aka SAP Security Note 2094830.
|
CWE-200
Information Exposure
|
CVE-2015-7731
|
2024-11-21 11:37 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212309
|
5.3 |
MEDIUM
Network
|
textpattern
|
textpattern
|
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
|
CWE-521
Weak Password Requirements
|
CVE-2015-8033
|
2024-11-21 11:37 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212310
|
5.3 |
MEDIUM
Network
|
textpattern
|
textpattern
|
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
|
CWE-269
Improper Privilege Management
|
CVE-2015-8032
|
2024-11-21 11:37 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|