|
293271
|
- |
|
mf_gig_calendar_project
|
mf_gig_calendar
|
Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the query string to the calendar page.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4242
|
2024-11-21 10:42 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293272
|
- |
|
eucalyptus
|
eucalyptus
|
Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to bypass unspecified authorization checks and obtain di…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4065
|
2024-11-21 10:42 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293273
|
- |
|
eucalyptus
|
eucalyptus
|
Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to gain privileges by sending a message to (1) Cloud Con…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4064
|
2024-11-21 10:42 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293274
|
- |
|
eucalyptus
|
eucalyptus
|
The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4063
|
2024-11-21 10:42 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293275
|
- |
|
fedoraproject
|
389_directory_server
|
389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restriction…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4450
|
2024-11-21 10:42 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293276
|
- |
|
smarty
|
smarty
|
Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors t…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4437
|
2024-11-21 10:42 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293277
|
- |
|
optipng
|
optipng
|
Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction."
|
CWE-399
Resource Management Errors
|
CVE-2012-4432
|
2024-11-21 10:42 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293278
|
- |
|
gnome
|
gnome-shell
|
The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.
|
CWE-94
Code Injection
|
CVE-2012-4427
|
2024-11-21 10:42 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293279
|
- |
|
fedoraproject guac-dev
|
fedora guacamole
|
Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a l…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-4415
|
2024-11-21 10:42 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293280
|
- |
|
david_king
|
vino
|
Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.
|
CWE-200
Information Exposure
|
CVE-2012-4429
|
2024-11-21 10:42 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|