CVE-2015-1982
published 2015-07-20CVE-2015-1982: IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive…
PriorityP412medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
0.95%
57.5th percentile
IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | infosphere_master_data_management | — | — |
| ibm | infosphere_master_data_management | — | — |
| ibm | infosphere_master_data_management | — | — |
| ibm | infosphere_master_data_management | — | — |
| ibm | infosphere_master_data_management | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7197 Mozilla: Mixed content WebSocket policy bypass through workers (MFSA 2015-132)
bugzilla·2015-11-03·CVSS 5.0
CVE-2015-7197 [MEDIUM] CVE-2015-7197 Mozilla: Mixed content WebSocket policy bypass through workers (MFSA 2015-132)
CVE-2015-7197 Mozilla: Mixed content WebSocket policy bypass through workers (MFSA 2015-132)
Mozilla developer Ehsan Akhgari reported a mechanism through which a web worker could be used to bypass secure requirements for WebSockets when workers are used to create WebSockets. This allows for the bypassing of mixed content WebSocket policy.
External Reference:
https://www.mozilla.org/security/announce/2015/mfsa2015-132.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Ehsan Akhgari as the original reporter.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2015:1982 https://rhn.redhat.com/errata/RHSA-2015-
Bugzilla
CVE-2015-7189 Mozilla: Buffer overflow during image interactions in canvas (MFSA 2015-123)
bugzilla·2015-11-03·CVSS 6.8
CVE-2015-7189 [MEDIUM] CVE-2015-7189 Mozilla: Buffer overflow during image interactions in canvas (MFSA 2015-123)
CVE-2015-7189 Mozilla: Buffer overflow during image interactions in canvas (MFSA 2015-123)
Security researcher Looben Yang reported a buffer overflow in the JPEGEncoder function during script interactions with a canvas element. This is caused by a race condition and incorrectly matched sizes following image interactions. This leads to a potentially exploitable crash.
External Reference:
https://www.mozilla.org/security/announce/2015/mfsa2015-123.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Looben Yang as the original reporter.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2015:1982 https://rhn.r
Bugzilla
CVE-2015-7194 Mozilla: Memory corruption in libjar through zip files (MFSA 2015-128)
bugzilla·2015-11-03·CVSS 7.5
CVE-2015-7194 [HIGH] CVE-2015-7194 Mozilla: Memory corruption in libjar through zip files (MFSA 2015-128)
CVE-2015-7194 Mozilla: Memory corruption in libjar through zip files (MFSA 2015-128)
Security researcher Gustavo Grieco reported a buffer underflow in libjar triggered through a maliciously crafted ZIP format file. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/security/announce/2015/mfsa2015-128.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Gustavo Grieco as the original reporter.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2015:1982 https://rhn.redhat.com/errata/RHSA-2015-1982.html
2015-07-20
Published