|
211401
|
7.5 |
HIGH
Network
|
docker
|
notary
|
In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the field specifying the signature algorithm, they might (…
|
CWE-310
Cryptographic Issues
|
CVE-2015-9258
|
2024-11-21 11:40 |
2018-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211402
|
6.1 |
MEDIUM
Network
|
bmc
|
remedy_action_request_system
|
BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9257
|
2024-11-21 11:40 |
2018-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211403
|
5.3 |
MEDIUM
Network
|
datto
|
alto_3_firmware alto_2_firmware alto_xl_firmware siris_3_firmware siris_2_firmware siris_3_x_all-flash_firmware siris_virtual_firmware alto_imaged_firmware
|
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default.
|
CWE-200
Information Exposure
|
CVE-2015-9256
|
2024-11-21 11:40 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211404
|
5.3 |
MEDIUM
Network
|
datto
|
alto_3_firmware alto_2_firmware alto_xl_firmware siris_3_firmware siris_2_firmware siris_3_x_all-flash_firmware siris_virtual_firmware alto_imaged_firmware
|
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory.
|
CWE-200
Information Exposure
|
CVE-2015-9255
|
2024-11-21 11:40 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211405
|
9.8 |
CRITICAL
Network
|
datto
|
alto_3_firmware alto_2_firmware alto_xl_firmware siris_3_firmware siris_2_firmware siris_3_x_all-flash_firmware siris_virtual_firmware alto_imaged_firmware
|
Datto ALTO and SIRIS devices have a default VNC password.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2015-9254
|
2024-11-21 11:40 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211406
|
6.5 |
MEDIUM
Network
|
php
|
php
|
An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution fun…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-9253
|
2024-11-21 11:40 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211407
|
5.5 |
MEDIUM
Local
|
qpdf_project
|
qpdf
|
An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizer.cc, related to the QPDF::resolve function in QPDF.cc.
|
CWE-399
Resource Management Errors
|
CVE-2015-9252
|
2024-11-21 11:40 |
2018-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211408
|
6.1 |
MEDIUM
Network
|
jquery oracle
|
jquery service_bus primavera_unifier jd_edwards_enterpriseone_tools enterprise_manager_ops_center webcenter_sites weblogic_server jdeveloper primavera_gateway peoplesoft_en…
|
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9251
|
2024-11-21 11:40 |
2018-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211409
|
7.5 |
HIGH
Network
|
skyboxsecurity
|
skybox_platform
|
An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmentdownload and /skyboxview/webskybox/filedownload via the tempFileName parameter.
|
CWE-22
Path Traversal
|
CVE-2015-9250
|
2024-11-21 11:40 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211410
|
9.8 |
CRITICAL
Network
|
skyboxsecurity
|
skybox_platform
|
An issue was discovered in Skybox Platform before 7.5.201. SQL Injection exists in /skyboxview/webservice/services/VersionWebService via a soapenv:Body element.
|
CWE-89
SQL Injection
|
CVE-2015-9249
|
2024-11-21 11:40 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|