Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 54 066

Количество 54 066

redhat логотип

CVE-2015-5252

больше 10 лет назад

vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2015-5251

почти 11 лет назад

OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2015-5250

почти 11 лет назад

The API server in OpenShift Origin 1.0.5 allows remote attackers to cause a denial of service (master process crash) via crafted JSON data.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2015-5248

больше 11 лет назад

Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-5247

почти 11 лет назад

The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2015-5246

почти 11 лет назад

The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.

CVSS2: 4.9
EPSS: Низкий
redhat логотип

CVE-2015-5245

почти 11 лет назад

CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.

CVSS2: 5.5
EPSS: Низкий
redhat логотип

CVE-2015-5244

почти 11 лет назад

The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass application restrictions.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-5242

почти 11 лет назад

OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs).

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2015-5241

около 11 лет назад

After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect the browser to an unintended web page in Apache jUDDI 3.1.2, 3.1.3, 3.1.4, and 3.1.5 when utilizing the portlets based user interface also known as 'Pluto', 'jUDDI Portal', 'UDDI Portal' or 'uddi-console'. User session data, credentials, and auth tokens are cleared before the redirect.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2015-5240

почти 11 лет назад

Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied.

CVSS2: 4.9
EPSS: Низкий
redhat логотип

CVE-2015-5239

около 12 лет назад

Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2015-5237

почти 11 лет назад

protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2015-5236

почти 5 лет назад

It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2015-5235

почти 11 лет назад

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-5234

почти 11 лет назад

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-5233

почти 11 лет назад

Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to delete reports from arbitrary hosts via direct access to the (a) individual report show/delete pages or (b) APIs.

CVSS2: 5.5
EPSS: Низкий
redhat логотип

CVE-2015-5232

почти 11 лет назад

Race conditions in opa-fm before 10.4.0.0.196 and opa-ff before 10.4.0.0.197.

CVSS2: 4.4
EPSS: Низкий
redhat логотип

CVE-2015-5231

почти 11 лет назад

The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2015-5229

почти 11 лет назад

The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2015-5252

vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points outside of a share.

CVSS2: 4.3
13%
Средний
больше 10 лет назад
redhat логотип
CVE-2015-5251

OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.

CVSS2: 6
2%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5250

The API server in OpenShift Origin 1.0.5 allows remote attackers to cause a denial of service (master process crash) via crafted JSON data.

CVSS2: 4
2%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5248

Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
redhat логотип
CVE-2015-5247

The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.

CVSS2: 1.7
1%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5246

The LDAP Authentication functionality in Foreman might allow remote attackers with knowledge of old passwords to gain access via vectors involving the password lifetime period in Active Directory.

CVSS2: 4.9
1%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5245

CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.

CVSS2: 5.5
2%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5244

The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass application restrictions.

CVSS2: 4.3
3%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5242

OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs).

CVSS2: 6
2%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5241

After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect the browser to an unintended web page in Apache jUDDI 3.1.2, 3.1.3, 3.1.4, and 3.1.5 when utilizing the portlets based user interface also known as 'Pluto', 'jUDDI Portal', 'UDDI Portal' or 'uddi-console'. User session data, credentials, and auth tokens are cleared before the redirect.

CVSS3: 5.3
2%
Низкий
около 11 лет назад
redhat логотип
CVE-2015-5240

Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied.

CVSS2: 4.9
1%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5239

Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.

CVSS2: 4
4%
Низкий
около 12 лет назад
redhat логотип
CVE-2015-5237

protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.

CVSS2: 2.6
5%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5236

It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not have to match the applet's actual origin, this allowed malicious site to bypass SOP via spoofed codebase value.

CVSS2: 5.8
1%
Низкий
почти 5 лет назад
redhat логотип
CVE-2015-5235

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

CVSS2: 4.3
3%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5234

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

CVSS2: 4.3
2%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5233

Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to delete reports from arbitrary hosts via direct access to the (a) individual report show/delete pages or (b) APIs.

CVSS2: 5.5
1%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5232

Race conditions in opa-fm before 10.4.0.0.196 and opa-ff before 10.4.0.0.197.

CVSS2: 4.4
2%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5231

The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access.

CVSS2: 2.1
0%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-5229

The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.

CVSS2: 2.6
2%
Низкий
почти 11 лет назад

Уязвимостей на страницу