|
291011
|
8.8 |
HIGH
Network
|
fedoraproject
|
sssd
|
A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup o…
|
CWE-287
Improper Authentication
|
CVE-2012-3462
|
2024-11-21 10:40 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291012
|
7.8 |
HIGH
Local
|
ecryptfs debian
|
ecryptfs-utils debian_linux
|
ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation
|
CWE-20
Improper Input Validation
|
CVE-2012-3409
|
2024-11-21 10:40 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291013
|
7.8 |
HIGH
Local
|
plow_project
|
plow
|
plow has local buffer overflow vulnerability
|
CWE-120
Classic Buffer Overflow
|
CVE-2012-3407
|
2024-11-21 10:40 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291014
|
9.8 |
CRITICAL
Network
|
redhat
|
enterprise_mrg
|
cumin: At installation postgresql database user created without password
|
CWE-20
Improper Input Validation
|
CVE-2012-3460
|
2024-11-21 10:40 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291015
|
7.5 |
HIGH
Network
|
freebsd
|
name_server_daemon
|
FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2012-2979
|
2024-11-21 10:40 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291016
|
7.5 |
HIGH
Network
|
apache
|
hadoop
|
Hadoop 1.0.3 contains a symlink vulnerability.
|
CWE-59
Link Following
|
CVE-2012-2945
|
2024-11-21 10:40 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291017
|
5.3 |
MEDIUM
Network
|
ibm
|
sametime
|
IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID: 78048.
|
CWE-200
Information Exposure
|
CVE-2012-3331
|
2024-11-21 10:40 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291018
|
7.5 |
HIGH
Network
|
apache
|
sling_jcr_contentloader
|
The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing po…
|
CWE-200
Information Exposure
|
CVE-2012-3353
|
2024-11-21 10:40 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291019
|
- |
|
seogento
|
seogento
|
Cross-site scripting (XSS) vulnerability in the SEOgento plugin for Magento allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this informat…
|
CWE-79
Cross-site Scripting
|
CVE-2012-3243
|
2024-11-21 10:40 |
2015-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291020
|
- |
|
spiceworks
|
spiceworks
|
SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json. NOTE: this entry was SPLIT per ADT2 due t…
|
CWE-89
SQL Injection
|
CVE-2012-2956
|
2024-11-21 10:40 |
2014-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|