|
293731
|
- |
|
apache
|
traffic_server
|
Apache Traffic Server 2.0.x and 3.0.x before 3.0.4 and 3.1.x before 3.1.3 does not properly allocate heap memory, which allows remote attackers to cause a denial of service (daemon crash) via a long …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-0256
|
2024-11-21 10:34 |
2012-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293732
|
- |
|
apache
|
wicket
|
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-0047
|
2024-11-21 10:34 |
2012-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293733
|
- |
|
rsa
|
envision
|
Directory traversal vulnerability in EMC RSA enVision 4.x before 4.1 Patch 4 allows remote authenticated users to have an unspecified impact via unknown vectors.
|
CWE-22
Path Traversal
|
CVE-2012-0403
|
2024-11-21 10:34 |
2012-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293734
|
- |
|
rsa
|
envision
|
EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access via unknown vectors.
|
CWE-255
Credentials Management
|
CVE-2012-0402
|
2024-11-21 10:34 |
2012-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293735
|
- |
|
rsa
|
envision
|
Multiple SQL injection vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2012-0401
|
2024-11-21 10:34 |
2012-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293736
|
- |
|
rsa
|
envision
|
EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
|
CWE-287
Improper Authentication
|
CVE-2012-0400
|
2024-11-21 10:34 |
2012-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293737
|
- |
|
rsa
|
envision
|
Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA enVision 4.x before 4.1 Patch 4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-0399
|
2024-11-21 10:34 |
2012-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293738
|
- |
|
janetter
|
janetter
|
Janetter before 3.3.0.0 (aka 3.3.0) allows remote attackers to obtain session information for twitter.com web sites via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2012-0328
|
2024-11-21 10:34 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293739
|
- |
|
golismero
|
golismero
|
libs/updater.py in GoLismero 0.6.3, and other versions before Git revision 2b3bb43d6867, as used in backtrack and possibly other products, allows local users to overwrite arbitrary files via a symlin…
|
CWE-59
Link Following
|
CVE-2012-0054
|
2024-11-21 10:34 |
2012-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293740
|
- |
|
tetsuya_aoyama
|
twicca
|
The twicca application 0.7.0 through 0.9.30 for Android does not properly restrict the use of network privileges, which allows remote attackers to read media files on an SD card via a crafted applica…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-0326
|
2024-11-21 10:34 |
2012-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|