|
292301
|
- |
|
scott_wheeler
|
taglib
|
Integer overflow in the mid function in toolkit/tbytevector.cpp in TagLib 1.7 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted file header…
|
CWE-189
Numeric Errors
|
CVE-2012-1584
|
2024-11-21 10:37 |
2012-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292302
|
- |
|
coppermine-gallery
|
coppermine_photo_gallery
|
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat paramete…
|
CWE-200
Information Exposure
|
CVE-2012-1614
|
2024-11-21 10:37 |
2012-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292303
|
- |
|
coppermine-gallery
|
coppermine_photo_gallery
|
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote authenticated users with certain privileges to inject arbitrary web script or HTML…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1613
|
2024-11-21 10:37 |
2012-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292304
|
- |
|
typo3
|
typo3
|
The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection …
|
CWE-20
Improper Input Validation
|
CVE-2012-1608
|
2024-11-21 10:37 |
2012-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292305
|
- |
|
typo3
|
typo3
|
The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to obtain the database name via a direct request.
|
CWE-200
Information Exposure
|
CVE-2012-1607
|
2024-11-21 10:37 |
2012-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292306
|
- |
|
typo3
|
typo3
|
Multiple cross-site scripting (XSS) vulnerabilities in the Backend component in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allow remote authenticated backend …
|
CWE-79
Cross-site Scripting
|
CVE-2012-1606
|
2024-11-21 10:37 |
2012-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292307
|
- |
|
typo3
|
typo3
|
The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute arbitrary code via ve…
|
NVD-CWE-Other
|
CVE-2012-1605
|
2024-11-21 10:37 |
2012-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292308
|
- |
|
oracle
|
jdk jre
|
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via u…
|
NVD-CWE-noinfo
|
CVE-2012-1682
|
2024-11-21 10:37 |
2012-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292309
|
- |
|
giantrobot
|
zipcart
|
The ZipCart module 6.x before 6.x-1.4 for Drupal checks the "access content" permission instead of the "access ZipCart downloads" permission when building archives, which allows remote authenticated …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1650
|
2024-11-21 10:37 |
2012-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292310
|
- |
|
mediafront
|
mediafront
|
Multiple cross-site scripting (XSS) vulnerabilities in the "stand alone PHP application for the OSM Player," as used in the MediaFront module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Dru…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1647
|
2024-11-21 10:37 |
2012-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|