|
294341
|
- |
|
realnetworks
|
realplayer realplayer_sp
|
RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via vectors involving a VIDOBJ_START_CODE code in …
|
CWE-94
Code Injection
|
CVE-2012-0924
|
2024-11-21 10:35 |
2012-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294342
|
- |
|
realnetworks
|
realplayer realplayer_sp
|
The RV20 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle the frame size array, which allows remote attackers to ex…
|
CWE-94
Code Injection
|
CVE-2012-0923
|
2024-11-21 10:35 |
2012-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294343
|
- |
|
realnetworks
|
realplayer realplayer_sp
|
rvrender.dll in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via crafted flags in an RMFF file.
|
CWE-94
Code Injection
|
CVE-2012-0922
|
2024-11-21 10:35 |
2012-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294344
|
- |
|
php
|
php
|
The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handl…
|
CWE-399
Resource Management Errors
|
CVE-2012-0830
|
2024-11-21 10:35 |
2012-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294345
|
- |
|
todd_miller
|
sudo
|
Format string vulnerability in the sudo_debug function in Sudo 1.8.0 through 1.8.3p1 allows local users to execute arbitrary code via format string sequences in the program name for sudo.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2012-0809
|
2024-11-21 10:35 |
2012-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294346
|
- |
|
samba
|
samba
|
Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.
|
CWE-200
Information Exposure
|
CVE-2012-0817
|
2024-11-21 10:35 |
2012-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294347
|
- |
|
wordpress
|
wordpress
|
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2012-0782
|
2024-11-21 10:35 |
2012-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294348
|
- |
|
acidcat
|
acidcat_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in Acidcat CMS 3.5.1, 3.5.2, 3.5.6, and possibly earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) adm…
|
CWE-79
Cross-site Scripting
|
CVE-2012-0933
|
2024-11-21 10:35 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294349
|
- |
|
leadcapturepagesystem
|
lead_capture_page_system
|
Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to inject arbitrary web script or HTML via the message parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-0932
|
2024-11-21 10:35 |
2012-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294350
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
modicon_quantum_plc
|
Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary cod…
|
CWE-287
Improper Authentication
|
CVE-2012-0931
|
2024-11-21 10:35 |
2012-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|