|
295221
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
Joomla! before 2.5.3 allows Admin Account Creation.
|
CWE-269
Improper Privilege Management
|
CVE-2012-1563
|
2024-11-21 10:37 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295222
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
Joomla! core before 2.5.3 allows unauthorized password change.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2012-1562
|
2024-11-21 10:37 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295223
|
9.8 |
CRITICAL
Network
|
openbsd dietlibc_project debian
|
openbsd dietlibc debian_linux
|
lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.
|
CWE-335
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
|
CVE-2012-1577
|
2024-11-21 10:37 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295224
|
7.8 |
HIGH
Local
|
fedoraproject
|
fedora sectool
|
A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.
|
CWE-269
Improper Privilege Management
|
CVE-2012-1615
|
2024-11-21 10:37 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295225
|
8.8 |
HIGH
Network
|
apache
|
struts
|
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2012-1592
|
2024-11-21 10:37 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295226
|
4.8 |
MEDIUM
Network
|
drupal
|
quick_tabs
|
Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1637
|
2024-11-21 10:37 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295227
|
7.5 |
HIGH
Network
|
openstack debian
|
keystone debian_linux
|
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2012-1572
|
2024-11-21 10:37 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295228
|
9.8 |
CRITICAL
Network
|
apache
|
ofbiz
|
Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2012-1622
|
2024-11-21 10:37 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295229
|
- |
|
oscmax
|
oscmax
|
Multiple SQL injection vulnerabilities in the admin panel in osCMax before 2.5.1 allow (1) remote attackers to execute arbitrary SQL commands via the username parameter in a process action to admin/l…
|
CWE-89
SQL Injection
|
CVE-2012-1665
|
2024-11-21 10:37 |
2015-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295230
|
- |
|
oscmax
|
oscmax
|
Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in osCMax before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter in a process…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1664
|
2024-11-21 10:37 |
2015-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|