|
292281
|
- |
|
redhat
|
enterprise_virtualization_manager
|
The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1 does not properly check privileges, which allows remote authenticated users to query arbitrary information via a (1) SOAP …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2696
|
2024-11-21 10:39 |
2013-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292282
|
- |
|
linux
|
linux_kernel
|
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netli…
|
CWE-20
Improper Input Validation
|
CVE-2012-2669
|
2024-11-21 10:39 |
2012-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292283
|
- |
|
microsoft
|
windows_server_2008 windows_rt windows_xp windows_7 windows_8 windows_server_2003 windows_vista windows_2003_server windows_server_2012
|
The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and …
|
CWE-94
Code Injection
|
CVE-2012-2556
|
2024-11-21 10:39 |
2012-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292284
|
- |
|
microsoft
|
windows_server_2008 windows_server_2012
|
The IP-HTTPS server in Windows Server 2008 R2 and R2 SP1 and Server 2012 does not properly validate certificates, which allows remote attackers to bypass intended access restrictions via a revoked ce…
|
CWE-20
Improper Input Validation
|
CVE-2012-2549
|
2024-11-21 10:39 |
2012-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292285
|
- |
|
xen
|
xen
|
Xen 4.0, and 4.1, when running a 64-bit PV guest on "older" AMD CPUs, does not properly protect against a certain AMD processor bug, which allows local guest OS users to cause a denial of service (ho…
|
NVD-CWE-noinfo
|
CVE-2012-2934
|
2024-11-21 10:39 |
2012-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292286
|
- |
|
oracle
|
jdk jre openjdk
|
Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without restricting the ability to trigger hash collisions predictably, which allows co…
|
CWE-310
Cryptographic Issues
|
CVE-2012-2739
|
2024-11-21 10:39 |
2012-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292287
|
- |
|
awcm-cms
|
ar_web_content_manager
|
ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows remote attackers to cause a denial of service (disk consump…
|
CWE-399
Resource Management Errors
|
CVE-2012-2438
|
2024-11-21 10:39 |
2012-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292288
|
- |
|
awcm-cms
|
ar_web_content_manager
|
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content…
|
CWE-287
Improper Authentication
|
CVE-2012-2437
|
2024-11-21 10:39 |
2012-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292289
|
- |
|
apache
|
tomcat
|
java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which …
|
CWE-20
Improper Input Validation
|
CVE-2012-2733
|
2024-11-21 10:39 |
2012-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292290
|
- |
|
broadcom apple
|
bcm4329 bcm4325 iphone_os
|
The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung, and Sony products, allow remote attackers to cau…
|
CWE-20
Improper Input Validation
|
CVE-2012-2619
|
2024-11-21 10:39 |
2012-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|