|
289171
|
- |
|
mjsware
|
m-player
|
M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file.
|
CWE-20
Improper Input Validation
|
CVE-2012-6044
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289172
|
- |
|
php-fusion
|
php-fusion
|
Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6043
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289173
|
- |
|
geopainting
|
gpsmapedit
|
GPSMapEdit 1.1.73.2 allows user-assisted remote attackers to cause a denial of service (crash) via a long string in a lst file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-6042
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289174
|
- |
|
morequick
|
greenbrowser
|
Double free vulnerability in GreenBrowser before 6.0.1002, when the keyword search bar (F6) is activated, allows remote attackers to execute arbitrary code via a crafted iframe.
|
CWE-399
Resource Management Errors
|
CVE-2012-6041
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289175
|
- |
|
convergine
|
file_king_advanced_file_management
|
Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6040
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289176
|
- |
|
yabsoft
|
advanced_image_hosting_script
|
SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows remote attackers to execute arbitrary SQL commands via the gal parameter.
|
CWE-89
SQL Injection
|
CVE-2012-6039
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289177
|
- |
|
razorcms
|
razorcms
|
admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, mov…
|
CWE-22
Path Traversal
|
CVE-2012-6038
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289178
|
- |
|
mahara
|
mahara
|
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6037
|
2024-11-21 10:45 |
2012-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289179
|
- |
|
xen
|
xen
|
The (1) memc_save_get_next_page, (2) tmemc_restore_put_page and (3) tmemc_restore_flush_page functions in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 do not check for negative id pools, w…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6036
|
2024-11-21 10:45 |
2012-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289180
|
- |
|
xen
|
xen
|
The do_tmem_destroy_pool function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 does not properly validate pool ids, which allows local guest OS users to cause a denial of service (memor…
|
CWE-20
Improper Input Validation
|
CVE-2012-6035
|
2024-11-21 10:45 |
2012-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|