|
290291
|
- |
|
realnetworks
|
realplayer
|
Stack-based buffer overflow in RealNetworks RealPlayer 15.0.5.109 allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP file that triggers incorrect processing of long pat…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-4987
|
2024-11-21 10:43 |
2012-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290292
|
- |
|
morbus_iff
|
activism
|
The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, which might allow remote attackers to bypass access restrictions and possibly h…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4498
|
2024-11-21 10:43 |
2012-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290293
|
- |
|
devsaran
|
elegant_theme
|
Cross-site scripting (XSS) vulnerability in the "3 slide gallery" in the Elegant Theme module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permissi…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4497
|
2024-11-21 10:43 |
2012-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290294
|
- |
|
roy_baxter
|
better_revisions
|
Cross-site scripting (XSS) vulnerability in the administrative interface in the Better Revisions module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer better…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4493
|
2024-11-21 10:43 |
2012-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290295
|
- |
|
gecad
|
axigen_free_mail_server
|
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote attackers to read or delete arbitrary files via a .. (dot dot) in (1) the fileName…
|
CWE-22
Path Traversal
|
CVE-2012-4940
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290296
|
- |
|
solarwinds
|
orion_network_performance_monitor ip_address_manager_web_interface
|
Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject ar…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4939
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290297
|
- |
|
xen
|
xen
|
The PV domain builder in Xen 4.2 and earlier does not validate the size of the kernel or ramdisk (1) before or (2) after decompression, which allows local guest administrators to cause a denial of se…
|
CWE-20
Improper Input Validation
|
CVE-2012-4544
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290298
|
- |
|
joomla
|
joomla\!
|
Cross-site scripting (XSS) vulnerability in modules/mod_languages/tmpl/default.php in the Language Switcher module for Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4532
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290299
|
- |
|
joomla
|
joomla\!
|
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.x before 2.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4531
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290300
|
- |
|
nancy_wichmann
|
announcements
|
The Announcements module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the "access announcements" permission to bypass node access restrictions and possibly have other unsp…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4500
|
2024-11-21 10:43 |
2012-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|