|
291671
|
- |
|
seagate
|
blackarmor_nas
|
d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2568
|
2024-11-21 10:39 |
2012-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291672
|
- |
|
xarrow
|
xarrow
|
The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecified vectors.
|
CWE-189
Numeric Errors
|
CVE-2012-2429
|
2024-11-21 10:39 |
2012-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291673
|
- |
|
xarrow
|
xarrow
|
Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers an out-of-bounds read operation.
|
CWE-189
Numeric Errors
|
CVE-2012-2428
|
2024-11-21 10:39 |
2012-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291674
|
- |
|
xarrow
|
xarrow
|
Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger an invalid free operation.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-2427
|
2024-11-21 10:39 |
2012-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291675
|
- |
|
xarrow
|
xarrow
|
The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors.
|
CWE-399
Resource Management Errors
|
CVE-2012-2426
|
2024-11-21 10:39 |
2012-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291676
|
- |
|
netweblogic
|
login_with_ajax
|
Cross-site scripting (XSS) vulnerability in login-with-ajax.php in the Login With Ajax (aka login-with-ajax) plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2759
|
2024-11-21 10:39 |
2012-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291677
|
- |
|
atlassian gliffy
|
jira gliffy confluence_server
|
The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to re…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2928
|
2024-11-21 10:39 |
2012-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291678
|
- |
|
tm_software
|
tempo tempo6.3.0 tempo6.3.2
|
The TM Software Tempo plugin before 6.4.3.1, 6.5.x before 6.5.0.2, and 7.x before 7.0.3 for Atlassian JIRA does not properly restrict the capabilities of third-party XML parsers, which allows remote …
|
CWE-399
Resource Management Errors
|
CVE-2012-2927
|
2024-11-21 10:39 |
2012-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291679
|
- |
|
xelex
|
mobiletrack
|
The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP sessio…
|
CWE-255
Credentials Management
|
CVE-2012-2567
|
2024-11-21 10:39 |
2012-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291680
|
- |
|
xelex
|
mobiletrack
|
The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows remote attackers to execute a (1) LOCATE, (2) TRACK, (3) UPDATECFG, (4) UPDATE…
|
CWE-287 CWE-20
Improper Authentication Improper Input Validation
|
CVE-2012-2562
|
2024-11-21 10:39 |
2012-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|