|
212371
|
- |
|
opensuse roundcube
|
opensuse webmail
|
Cross-site scripting (XSS) vulnerability in program/js/app.js in Roundcube webmail before 1.0.7 and 1.1.x before 1.1.3 allows remote authenticated users to inject arbitrary web script or HTML via the…
|
CWE-79
Cross-site Scripting
|
CVE-2015-8105
|
2024-11-21 11:38 |
2015-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212372
|
- |
|
net-snmp
|
net-snmp
|
The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf, which allows local users to obtain sensitive community information by reading this file.
|
CWE-200
Information Exposure
|
CVE-2015-8100
|
2024-11-21 11:38 |
2015-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212373
|
- |
|
google
|
picasa
|
Integer overflow in Google Picasa 3.9.140 Build 239 and Build 248 allows remote attackers to execute arbitrary code via unspecified vectors related to "phase one 0x412 tag," which triggers a heap-bas…
|
CWE-119 CWE-189
Incorrect Access of Indexable Resource ('Range Error') Numeric Errors
|
CVE-2015-8096
|
2024-11-21 11:38 |
2015-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212374
|
- |
|
monster_menus_module_project
|
monster_menus
|
The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote attackers to obtain sensitive information via an …
|
CWE-200
Information Exposure
|
CVE-2015-8095
|
2024-11-21 11:38 |
2015-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212375
|
9.8 |
CRITICAL
Network
|
eclipse
|
hudson
|
Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks.
|
CWE-611
XXE
|
CVE-2015-8031
|
2024-11-21 11:37 |
2022-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212376
|
5.5 |
MEDIUM
Local
|
sap
|
mobile_platform
|
SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the DataVault, aka SAP Security Note 2094830.
|
CWE-200
Information Exposure
|
CVE-2015-7731
|
2024-11-21 11:37 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212377
|
5.3 |
MEDIUM
Network
|
textpattern
|
textpattern
|
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
|
CWE-521
Weak Password Requirements
|
CVE-2015-8033
|
2024-11-21 11:37 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212378
|
5.3 |
MEDIUM
Network
|
textpattern
|
textpattern
|
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
|
CWE-269
Improper Privilege Management
|
CVE-2015-8032
|
2024-11-21 11:37 |
2020-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212379
|
4.6 |
MEDIUM
Physics
|
ubports
|
unity8
|
Information Exposure vulnerability in Unity8 as used on the Ubuntu phone and possibly also in Unity8 shipped elsewhere. This allows an attacker to enable the MTP service by opening the emergency dial…
|
CWE-200
Information Exposure
|
CVE-2015-7946
|
2024-11-21 11:37 |
2020-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212380
|
4.3 |
MEDIUM
Network
|
sap
|
netweaver_application_server
|
nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.
|
CWE-611
XXE
|
CVE-2015-7968
|
2024-11-21 11:37 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|