|
292251
|
- |
|
cisco
|
unified_computing_system
|
The Board Management Controller (BMC) in the Serial over LAN (SoL) subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded private key, which allows man-in-the-middle attackers to obt…
|
CWE-255
Credentials Management
|
CVE-2012-4074
|
2024-11-21 10:42 |
2013-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292252
|
- |
|
cisco
|
unified_computing_system
|
The KVM subsystem in the client in Cisco Unified Computing System (UCS) does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers, and read or mod…
|
CWE-310
Cryptographic Issues
|
CVE-2012-4073
|
2024-11-21 10:42 |
2013-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292253
|
- |
|
cisco
|
unified_computing_system
|
The KVM subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers, and read keyboard and mouse events, b…
|
CWE-20
Improper Input Validation
|
CVE-2012-4072
|
2024-11-21 10:42 |
2013-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292254
|
- |
|
eucalyptus
|
eucalyptus
|
Walrus in Eucalyptus before 3.2.2 allows remote attackers to cause a denial of service (memory, thread, and CPU consumption) via a crafted XML message containing a DTD, as demonstrated by a bucket-lo…
|
CWE-399
Resource Management Errors
|
CVE-2012-4067
|
2024-11-21 10:42 |
2013-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292255
|
- |
|
ruby-lang
|
ruby
|
The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method when operating on Ruby objects. NOTE: this issue is due to an incomplete fix f…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4481
|
2024-11-21 10:42 |
2013-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292256
|
- |
|
ruby-lang
|
ruby
|
Ruby 1.8.7 before patchlevel 371, 1.9.3 before patchlevel 286, and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4466
|
2024-11-21 10:42 |
2013-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292257
|
- |
|
ruby-lang
|
ruby
|
Ruby 1.9.3 before patchlevel 286 and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untainted strings via the (1) exc_to_s or (2) name_err_…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4464
|
2024-11-21 10:42 |
2013-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292258
|
- |
|
oracle
|
fusion_middleware
|
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 11.1.1.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to C…
|
NVD-CWE-noinfo
|
CVE-2012-4303
|
2024-11-21 10:42 |
2013-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292259
|
- |
|
condor_project redhat
|
condor enterprise_mrg
|
aviary/jobcontrol.py in Condor, as used in Red Hat Enterprise MRG 2.3, when removing a job, allows remote attackers to cause a denial of service (condor_schedd restart) via square brackets in the cpr…
|
CWE-20
Improper Input Validation
|
CVE-2012-4462
|
2024-11-21 10:42 |
2013-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292260
|
- |
|
apache
|
qpid
|
The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure and daemon exit) via …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-4460
|
2024-11-21 10:42 |
2013-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|