CVE-2015-5947
SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.
Read MoreSuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.
Read Moresvn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by using the “Command Shell” menu item while in the directory trunk/$(xeyes).
Read MoreXML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
Read MoreFroxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log.
Read MoreTinfoil Devise-two-factor before 2.0.0 does not strictly follow section 5.2 of RFC 6238 and does not “burn” a successfully validated one-time password (aka OTP), which allows remote or physically proximate attackers...
Read More