CVE-2016-2315 (git, leap, linux_enterprise_debuginfo, linux_enterprise_server, linux_enterprise_software_development_kit, openstack_cloud, opensuse)

CVE-2016-2315 (git, leap, linux_enterprise_debuginfo, linux_enterprise_server, linux_enterprise_software_development_kit, openstack_cloud, opensuse)

revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.

Source: CVE-2016-2315 (git, leap, linux_enterprise_debuginfo, linux_enterprise_server, linux_enterprise_software_development_kit, openstack_cloud, opensuse)

CVE-2015-6541 (zimbra_collaboration_server)

CVE-2015-6541 (zimbra_collaboration_server)

Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication of arbitrary users for requests that change account preferences via a SOAP request to service/soap/BatchRequest.

Source: CVE-2015-6541 (zimbra_collaboration_server)

CVE-2015-6541

CVE-2015-6541

Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication of arbitrary users for requests that change account preferences via a SOAP request to service/soap/BatchRequest.

Source: CVE-2015-6541

CVE-2015-8840 (netweaver)

CVE-2015-8840 (netweaver)

The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other impact via requests to (1) webcontent/cas/cas_enter.jsp, (2) webcontent/cas/cas_validate.jsp, or (3) webcontent/aas/aas_store.jsp, aka SAP Security Note 1945215.

Source: CVE-2015-8840 (netweaver)

CVE-2015-8840

CVE-2015-8840

The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other impact via requests to (1) webcontent/cas/cas_enter.jsp, (2) webcontent/cas/cas_validate.jsp, or (3) webcontent/aas/aas_store.jsp, aka SAP Security Note 1945215.

Source: CVE-2015-8840

CVE-2016-2851 (debian_linux, leap, libotr, opensuse)

CVE-2016-2851 (debian_linux, leap, libotr, opensuse)

Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-based buffer overflow.

Source: CVE-2016-2851 (debian_linux, leap, libotr, opensuse)