|
294531
|
- |
|
openssl
|
openssl
|
The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted d…
|
CWE-399
Resource Management Errors
|
CVE-2012-0027
|
2024-11-21 10:34 |
2012-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294532
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_asset_manager
|
IBM Rational Asset Manager 7.5 could allow a remote attacker to bypass security restrictions. An attacker could exploit this vulnerability using the UID parameter to modify another user's preferences.
|
NVD-CWE-Other
|
CVE-2011-4820
|
2024-11-21 10:33 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294533
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.
|
CWE-200
Information Exposure
|
CVE-2011-4916
|
2024-11-21 10:33 |
2022-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294534
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel through 3.1 there is an information disclosure issue via /proc/stat.
|
NVD-CWE-noinfo
|
CVE-2011-4917
|
2024-11-21 10:33 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294535
|
5.5 |
MEDIUM
Local
|
linux canonical debian
|
linux_kernel ubuntu_linux debian_linux
|
fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.
|
CWE-200
Information Exposure
|
CVE-2011-4915
|
2024-11-21 10:33 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294536
|
9.8 |
CRITICAL
Network
|
tiny
|
tinybrowser
|
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2011-4908
|
2024-11-21 10:33 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294537
|
9.8 |
CRITICAL
Network
|
tiny
|
tinybrowser
|
Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2011-4906
|
2024-11-21 10:33 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294538
|
6.1 |
MEDIUM
Network
|
muze
|
ariadne
|
Multiple cross-site scripting (XSS) vulnerabilities in Ariadne 2.7.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO parameter to (1) index.php and (2) loader.php.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4938
|
2024-11-21 10:33 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294539
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2011-4912
|
2024-11-21 10:33 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294540
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
Joomla! 1.7.1 has core information disclosure due to inadequate error checking.
|
CWE-200
Information Exposure
|
CVE-2011-4937
|
2024-11-21 10:33 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|