Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-2684 | 2 Debian, Shibboleth | 2 Debian Linux, Service Provider | 2016-12-02 | 4.0 MEDIUM | N/A |
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message. | |||||
CVE-2015-2701 | 1 Cs-cart | 1 Cs-cart | 2016-12-02 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of users for requests that change a user password via a request to profiles-update/. | |||||
CVE-2015-2704 | 1 Realmd Project | 1 Realmd | 2016-12-02 | 5.0 MEDIUM | N/A |
realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf via a newline character in an LDAP response. | |||||
CVE-2015-2753 | 2 Debian, Gaia-gis | 2 Debian Linux, Freexl | 2016-12-02 | 6.8 MEDIUM | N/A |
FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly execute arbitrary code via a crafted sector in a workbook. | |||||
CVE-2015-2757 | 1 Mcafee | 1 Data Loss Prevention Endpoint | 2016-12-02 | 4.0 MEDIUM | N/A |
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to cause a denial of service (database lock or license corruption) via unspecified vectors. | |||||
CVE-2015-2758 | 1 Mcafee | 1 Data Loss Prevention Endpoint | 2016-12-02 | 6.5 MEDIUM | N/A |
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain sensitive information, modify the database, or possibly have other unspecified impact via a crafted URL. | |||||
CVE-2015-2759 | 1 Mcafee | 1 Data Loss Prevention Endpoint | 2016-12-02 | 6.8 MEDIUM | N/A |
Multiple cross-site request forgery (CSRF) vulnerabilities in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allow remote attackers to hijack the authentication of users for requests that (1) obtain sensitive information or (2) modify the database via unspecified vectors. | |||||
CVE-2015-2115 | 1 Hp | 1 Capture And Route Software | 2016-12-02 | 2.7 LOW | N/A |
Unspecified vulnerability in HP Capture and Route Software (HPCR) 1.3 before Patch 7, 1.3 FP1 before Patch 1, and 1.4 before Patch 1 allows remote authenticated users to obtain sensitive information via unknown vectors. | |||||
CVE-2015-2116 | 1 Hp | 1 Storage Data Protector | 2016-12-02 | 9.0 HIGH | N/A |
Unspecified vulnerability in HP Storage Data Protector 7.x before 7.03 build 107 allows remote authenticated users to execute arbitrary code or cause a denial of service via unknown vectors. | |||||
CVE-2015-2117 | 1 Hp | 2 Tippingpoint Security Management System, Tippingpoint Virtual Security Management System | 2016-12-02 | 7.5 HIGH | N/A |
HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management System (vSMS) before 4.1 patch 3 and 4.2 before patch 1 do not require authentication for JBoss RMI requests, which allows remote attackers to execute arbitrary code by (1) uploading this code within an archive or (2) instantiating a class. | |||||
CVE-2015-2121 | 1 Hp | 1 Network Virtualization | 2016-12-02 | 7.8 HIGH | N/A |
HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename in a URL to the (1) HttpServlet or (2) NetworkEditorController component, aka ZDI-CAN-2569. | |||||
CVE-2015-2122 | 1 Hp | 1 Sdn Van Controller | 2016-12-02 | 7.8 HIGH | N/A |
The REST layer on HP SDN VAN Controller devices 2.5 and earlier allows remote attackers to cause a denial of service via network traffic to the REST port. | |||||
CVE-2015-2123 | 1 Hp | 1 Nonstop Safeguard Security | 2016-12-02 | 9.0 HIGH | N/A |
Unspecified vulnerability in HP NonStop Safeguard Security Software H06.x, L15.02, and J06.x before J06.19 allows remote authenticated users to gain privileges by leveraging Expand access. | |||||
CVE-2015-2124 | 1 Hp | 2 Smart Zero Core, Thinpro Linux | 2016-12-02 | 7.2 HIGH | N/A |
Unspecified vulnerability in Easy Setup Wizard in HP ThinPro Linux 4.1 through 5.1 and Smart Zero Core 4.3 and 4.4 allows local users to bypass intended access restrictions and gain privileges via unknown vectors. | |||||
CVE-2015-2166 | 1 Ericsson | 1 Drutt Mobile Service Delivery Platform | 2016-12-02 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI. | |||||
CVE-2015-2167 | 1 Ericsson | 1 Drutt Mobile Service Delivery Platform | 2016-12-02 | 5.8 MEDIUM | N/A |
Open redirect vulnerability in the 3PI Manager in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter to jsp/start-3pi-manager.jsp. | |||||
CVE-2015-2169 | 1 Zohocorp | 1 Manageengine Assetexplorer | 2016-12-02 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attackers to inject arbitrary web script or HTML via a Publisher registry entry, which is not properly handled when the machine is scanned. | |||||
CVE-2015-2171 | 1 Slimframework | 1 Slim | 2016-12-02 | 7.5 HIGH | N/A |
Middleware/SessionCookie.php in Slim before 2.6.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted session data. | |||||
CVE-2015-2194 | 1 Digitalnature | 1 Fusion | 2016-12-02 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in the fusion_options function in functions.php in the Fusion theme 3.1 for Wordpress allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension in a fusion_save action, then accessing it via unspecified vectors. | |||||
CVE-2015-2209 | 1 Dlguard | 1 Dlguard | 2016-12-02 | 5.0 MEDIUM | N/A |
DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php. |