|
290931
|
- |
|
cisco
|
vc240_network_bullet_camera video_surveillance_vc220_network_dome_camera
|
The Cisco VC220 and VC240 cameras allow remote attackers to cause a denial of service (WebUI outage) via crafted packets, aka Bug IDs CSCtf73188, CSCtf88059, CSCtf87951, CSCtf87908, and CSCtf88019.
|
NVD-CWE-noinfo
|
CVE-2012-3913
|
2024-11-21 10:41 |
2013-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290932
|
- |
|
apache
|
tomcat
|
Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming dat…
|
CWE-20
Improper Input Validation
|
CVE-2012-3544
|
2024-11-21 10:41 |
2013-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290933
|
- |
|
redhat
|
jboss_enterprise_portal_platform
|
Cross-site request forgery (CSRF) vulnerability in the GateIn Portal component in JBoss Enterprise Portal Platform 5.2.2 and earlier allows remote attackers to hijack the authentication of unspecifie…
|
CWE-352
Origin Validation Error
|
CVE-2012-3532
|
2024-11-21 10:41 |
2013-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290934
|
- |
|
apache
|
http_server
|
Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors …
|
CWE-79
Cross-site Scripting
|
CVE-2012-3499
|
2024-11-21 10:41 |
2013-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290935
|
- |
|
redhat
|
cloudforms
|
Pulp in Red Hat CloudForms before 1.1 logs administrative passwords in a world-readable file, which allows local users to read pulp administrative passwords by reading production.log.
|
CWE-255
Credentials Management
|
CVE-2012-3538
|
2024-11-21 10:41 |
2013-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290936
|
- |
|
openconstructor_project
|
openconstructor
|
Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) data/gallery/edit.php, (2) data/guestb…
|
CWE-89
SQL Injection
|
CVE-2012-3873
|
2024-11-21 10:41 |
2012-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290937
|
- |
|
openconstructor_project
|
openconstructor
|
Multiple cross-site scripting (XSS) vulnerabilities in Open Constructor 3.12.0 allow remote attackers to inject arbitrary web script or HTML via (1) the result parameter to data/file/edit.php, (2) th…
|
CWE-79
Cross-site Scripting
|
CVE-2012-3872
|
2024-11-21 10:41 |
2012-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290938
|
- |
|
openconstructor_project
|
openconstructor
|
Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authenticated users to inject arbitrary web script or HTML via the header parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-3871
|
2024-11-21 10:41 |
2012-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290939
|
- |
|
openconstructor_project
|
openconstructor
|
Multiple cross-site scripting (XSS) vulnerabilities in objects/createobject.php in Open Constructor 3.12.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) name or …
|
CWE-79
Cross-site Scripting
|
CVE-2012-3870
|
2024-11-21 10:41 |
2012-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290940
|
- |
|
apache
|
tomcat
|
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by le…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3546
|
2024-11-21 10:41 |
2012-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|