|
293171
|
- |
|
creative_commons_module_project
|
creativecommons
|
Multiple cross-site scripting (XSS) vulnerabilities in the Creative Commons module 6.x-1.x before 6.x-1.1 for Drupal allow remote authenticated users with the administer creative commons permission t…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2297
|
2024-11-21 10:38 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293172
|
- |
|
munin-monitoring
|
munin
|
munin-cgi-graph in Munin 2.0 rc4 allows remote attackers to cause a denial of service (disk or memory consumption) via many image requests with large values in the (1) size_x or (2) size_y parameters.
|
CWE-399
Resource Management Errors
|
CVE-2012-2147
|
2024-11-21 10:38 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293173
|
- |
|
ematia
|
elixir
|
Elixir 0.8.0 uses Blowfish in CFB mode without constructing a unique initialization vector (IV), which makes it easier for context-dependent users to obtain sensitive information and decrypt the data…
|
CWE-310
Cryptographic Issues
|
CVE-2012-2146
|
2024-11-21 10:38 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293174
|
- |
|
munin-monitoring
|
munin
|
cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote attackers to inject terminal emulator escape sequenc…
|
CWE-20
Improper Input Validation
|
CVE-2012-2104
|
2024-11-21 10:38 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293175
|
- |
|
munin-monitoring
|
munin
|
The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
|
CWE-59
Link Following
|
CVE-2012-2103
|
2024-11-21 10:38 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293176
|
- |
|
sitecom
|
wlm-2501
|
Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote attackers to hijack the authentication of administrators for requests that change the r…
|
CWE-352
Origin Validation Error
|
CVE-2012-1921
|
2024-11-21 10:38 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293177
|
- |
|
pluxml
|
pluxml
|
Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the default_la…
|
CWE-22
Path Traversal
|
CVE-2012-2227
|
2024-11-21 10:38 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293178
|
- |
|
emc
|
applicationxtender_web_access_.net applicationxtender_desktop
|
EMC ApplicationXtender Desktop before 6.5 SP2 and ApplicationXtender Web Access .NET before 6.5 SP2 allow remote attackers to upload files to any location, and possibly execute arbitrary code, via un…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2289
|
2024-11-21 10:38 |
2012-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293179
|
- |
|
ibm
|
websphere_application_server
|
IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1,…
|
CWE-310
Cryptographic Issues
|
CVE-2012-2190
|
2024-11-21 10:38 |
2012-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293180
|
- |
|
debian
|
devotee
|
devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers via a brute force attack.
|
CWE-200
Information Exposure
|
CVE-2012-2387
|
2024-11-21 10:38 |
2012-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|