|
292191
|
6.5 |
MEDIUM
Adjacent
|
quagga debian redhat
|
quagga debian_linux enterprise_linux
|
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
|
CWE-617
Reachable Assertion
|
CVE-2012-5521
|
2024-11-21 10:44 |
2019-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292192
|
7.5 |
HIGH
Network
|
ovirt
|
vdsm
|
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
|
CWE-295
Improper Certificate Validation
|
CVE-2012-5518
|
2024-11-21 10:44 |
2019-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292193
|
6.2 |
MEDIUM
Local
|
python
|
keyring
|
Python keyring has insecure permissions on new databases allowing world-readable files to be created
|
CWE-276
Incorrect Default Permissions
|
CVE-2012-5578
|
2024-11-21 10:44 |
2019-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292194
|
6.1 |
MEDIUM
Network
|
bitweaver
|
bitweaver
|
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsle…
|
CWE-79
Cross-site Scripting
|
CVE-2012-5193
|
2024-11-21 10:44 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292195
|
7.5 |
HIGH
Network
|
python debian
|
keyring debian_linux
|
Python keyring lib before 0.10 created keyring files with world-readable permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2012-5577
|
2024-11-21 10:44 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292196
|
8.8 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted QT file.
|
CWE-20
Improper Input Validation
|
CVE-2012-5360
|
2024-11-21 10:44 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292197
|
8.8 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted ASF file.
|
CWE-20
Improper Input Validation
|
CVE-2012-5359
|
2024-11-21 10:44 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292198
|
9.8 |
CRITICAL
Network
|
ektron
|
ektron_content_management_system
|
The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with enableDocumentFunction set to true, which allows remote attackers to read arbitrar…
|
CWE-19
Data Processing Errors
|
CVE-2012-5358
|
2024-11-21 10:44 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292199
|
9.8 |
CRITICAL
Network
|
ektron
|
ektron_content_management_system
|
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE …
|
CWE-19
Data Processing Errors
|
CVE-2012-5357
|
2024-11-21 10:44 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292200
|
7.8 |
HIGH
Local
|
ffmpeg
|
ffmpeg
|
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted WMV file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-5361
|
2024-11-21 10:44 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|