|
295531
|
- |
|
microsoft
|
windows_server_2008 windows_7 windows_xp windows_server_2003 windows_vista
|
Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and …
|
NVD-CWE-Other
|
CVE-2012-0013
|
2024-11-21 10:34 |
2012-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295532
|
- |
|
microsoft
|
windows_xp windows_server_2003
|
Untrusted search path vulnerability in the Windows Object Packager configuration in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse execu…
|
NVD-CWE-Other
|
CVE-2012-0009
|
2024-11-21 10:34 |
2012-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295533
|
- |
|
microsoft
|
anti-cross_site_scripting_library
|
The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remot…
|
CWE-79
Cross-site Scripting
|
CVE-2012-0007
|
2024-11-21 10:34 |
2012-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295534
|
- |
|
microsoft
|
windows_server_2008 windows_xp windows_server_2003 windows_vista
|
The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean syste…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-0005
|
2024-11-21 10:34 |
2012-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295535
|
- |
|
microsoft
|
windows_server_2008 windows_xp windows_7 windows_server_2003 windows_vista
|
Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1…
|
NVD-CWE-noinfo
|
CVE-2012-0004
|
2024-11-21 10:34 |
2012-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295536
|
- |
|
microsoft
|
windows_server_2008 windows_7 windows_xp windows_server_2003 windows_vista
|
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote a…
|
NVD-CWE-noinfo
|
CVE-2012-0003
|
2024-11-21 10:34 |
2012-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295537
|
- |
|
microsoft
|
windows_server_2008 windows_7 windows_xp windows_server_2003 windows_vista
|
The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly load structured exception han…
|
NVD-CWE-Other
|
CVE-2012-0001
|
2024-11-21 10:34 |
2012-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295538
|
- |
|
apache
|
struts
|
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor chara…
|
CWE-94
Code Injection
|
CVE-2012-0394
|
2024-11-21 10:34 |
2012-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295539
|
- |
|
apache
|
struts
|
The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted p…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-0393
|
2024-11-21 10:34 |
2012-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295540
|
- |
|
apache
|
struts
|
The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header…
|
NVD-CWE-noinfo
|
CVE-2012-0392
|
2024-11-21 10:34 |
2012-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|