Unknown · CVSS Not scored
IBM Systems Director 5.2.x, 6.1.x, 6.2.0.x, 6.2.1.x, 6.3.0.0, 6.3.1.x, 6.3.2.x, 6.3.3.x, 6.3.5.0, and 6.3.6.0 improperly processes events, which allows local users to gain privileges via unspecified vectors.
Published Aug 23, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1987.
Published Aug 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The IBM WebSphere DataPower XC10 appliance 2.1 through 2.1.0.3 and 2.5 through 2.5.0.4 retains data on SSD cards, which might allow physically proximate attackers to obtain sensitive information by extracting a card and attaching it elsewhere.
Published Aug 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1958 and CVE-2015-1987.
Published Aug 3, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Open redirect vulnerability in the web server in IBM Domino 8.5 before 8.5.3 FP6 IF9 and 9.0 before 9.0.1 FP4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via a crafted URL, aka SPR SJAR9DNGDA.
Published Aug 23, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header.
Published Aug 22, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0, when external Enterprise Content Management (ECM) integration is enabled with a certain technical system account configuration, allows remote authenticated users to bypass intended document-access restrictions via a (1) upload or (2) download action.
Published Aug 1, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in ES File Explorer 3.2.4.1.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
Published Aug 12, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Foreman before 1.7.5 allows remote authenticated users to bypass organization and location restrictions by connecting through the REST API.
Published Aug 14, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cookies set in a response to a redirect.
Published Aug 9, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in the Linux kernel before 3.16 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun."
Published Aug 8, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ before 11.72 allows physically proximate attackers to sign arbitrary data with previously loaded signing keys, extract the device identification key [KNETI] and impersonate the nShield Connect device on a network, affect the integrity and confidentiality of newly created keys, and potentially cause other unspecified impacts using previously loaded keys by connecting to the USB port on the front panel.
Published Aug 18, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a crafted certificate.
Published Aug 14, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.
Published Aug 14, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red Hat JBoss BPM Suite before 6.1.2 allows remote attackers to read arbitrary files, conduct server-side request forgery (SSRF) attacks, and have other unspecified impact via a crafted XML document.
Published Aug 11, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.
Published Aug 19, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in the inet_pton function in network/inet_pton.c in musl libc 0.9.15 through 1.0.4, and 1.1.0 through 1.1.7 allows attackers to have unspecified impact via unknown vectors.
Published Aug 18, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a denial of service (memory corruption) or gain privileges.
Published Aug 24, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to potentially obtain sensitive information.
Published Aug 24, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors.
Published Aug 11, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Information disclosure vulnerability in Netatmo Indoor Module firmware 100 and earlier.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Published Aug 1, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrary files, and consequently obtain administrator privileges, via a crafted filename.
Published Aug 1, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
kgb-bot 1.33-2 allows remote attackers to cause a denial of service (crash).
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using session validators.
Published Aug 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to read arbitrary files via a relative pathname in a client installation package.
Published Aug 1, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in the client in Symantec Endpoint Protection 12.1 before 12.1-RU6-MP1 allows local users to gain privileges via a Trojan horse DLL in a client install package.
Published Aug 1, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to gain privileges via unspecified vectors.
Published Aug 1, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An unspecified action handler in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to read arbitrary files via unknown vectors.
Published Aug 1, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers to bypass authentication via a crafted password-reset action that triggers a new administrative session.
Published Aug 1, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allows remote attackers to execute arbitrary code.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.
Published Aug 25, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in unshield 1.0-1.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
cmdlineopts.clp in grml-debootstrap in Debian 0.54, 0.68.x before 0.68.1, 0.7x before 0.78 is sourced without checking that the local directory is writable by non-root users.
Published Aug 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in xymon 4.3.17-1.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
attach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confinement by mounting a proc filesystem with a crafted (1) AppArmor profile or (2) SELinux label.
Published Aug 12, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
lxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.
Published Aug 12, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Memory leak in the __key_link_end function in security/keys/keyring.c in the Linux kernel before 4.1.4 allows local users to cause a denial of service (memory consumption) via many add_key system calls that refer to existing keys.
Published Aug 31, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write to arbitrary files and gain root privileges by leveraging incorrect handling of permissions when generating core dumps for setuid binaries.
Published Aug 25, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in ppmd 10.1-5.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple directory traversal vulnerabilities in ha 0.999p+dfsg-5.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in GSM SIM Utility (aka SIM Card Editor) 6.6 allows remote attackers to execute arbitrary code via a long entry in a .sms file.
Published Aug 28, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id.
Published Aug 2, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-middle attackers to obtain encryption keys, user credentials, and other sensitive information by sniffing the network or modify this traffic by inserting packets into the client-server data stream.
Published Aug 31, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in ZTE Datacard MF19 0V1.0.0B04 allows local users to gain privilege by modifying the 'Ucell Internet' directory to reference a malicious mms_dll_r.dll or mediaplayerdll.dll.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file.
Published Aug 1, 2015 · Updated Aug 6, 2024