|
294311
|
5.5 |
MEDIUM
Local
|
uzbl debian
|
uzbl debian_linux
|
uzbl: Information disclosure via world-readable cookies storage file
|
CWE-200
Information Exposure
|
CVE-2012-0843
|
2024-11-21 10:35 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294312
|
9.8 |
CRITICAL
Network
|
gnu
|
gnusound
|
gnusound 0.7.5 has format string issue
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2012-0824
|
2024-11-21 10:35 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294313
|
5.5 |
MEDIUM
Local
|
suckless debian
|
surf debian_linux
|
surf: cookie jar has read access from other local user
|
CWE-200
Information Exposure
|
CVE-2012-0842
|
2024-11-21 10:35 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294314
|
9.8 |
CRITICAL
Network
|
sugarcrm
|
sugarcrm
|
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
|
CWE-20
Improper Input Validation
|
CVE-2012-0694
|
2024-11-21 10:35 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294315
|
8.8 |
HIGH
Network
|
adobe
|
shockwave_player
|
Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-0771
|
2024-11-21 10:35 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294316
|
8.8 |
HIGH
Network
|
haudenschilt
|
family_connections_cms
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests tha…
|
CWE-352
Origin Validation Error
|
CVE-2012-0699
|
2024-11-21 10:35 |
2018-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294317
|
7.5 |
HIGH
Network
|
apache
|
xerces2_java
|
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
|
CWE-399
Resource Management Errors
|
CVE-2012-0881
|
2024-11-21 10:35 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294318
|
7.5 |
HIGH
Network
|
apache
|
xerces-c\+\+
|
Apache Xerces-C++ allows remote attackers to cause a denial of service (CPU consumption) via a crafted message sent to an XML service that causes hash table collisions.
|
CWE-399
Resource Management Errors
|
CVE-2012-0880
|
2024-11-21 10:35 |
2017-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294319
|
9.8 |
CRITICAL
Network
|
apache
|
cxf
|
The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as part of a SOAP request.
|
CWE-287
Improper Authentication
|
CVE-2012-0803
|
2024-11-21 10:35 |
2017-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294320
|
- |
|
postfix
|
postfix
|
Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt func…
|
CWE-89
SQL Injection
|
CVE-2012-0811
|
2024-11-21 10:35 |
2014-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|