|
291021
|
- |
|
ibm
|
smartcloud_control_desk maximo_asset_management
|
CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote attackers to inject arbitrary HT…
|
NVD-CWE-Other
|
CVE-2012-3333
|
2024-11-21 10:40 |
2014-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291022
|
- |
|
cisco
|
ios
|
Cisco IOS before 15.1(1)SY, when Multicast Listener Discovery (MLD) snooping is enabled, allows remote attackers to cause a denial of service (CPU consumption or device crash) via MLD packets on a ne…
|
CWE-20
Improper Input Validation
|
CVE-2012-3062
|
2024-11-21 10:40 |
2014-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291023
|
- |
|
redhat
|
conga enterprise_linux
|
Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this is…
|
CWE-255
Credentials Management
|
CVE-2012-3359
|
2024-11-21 10:40 |
2014-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291024
|
- |
|
canonical redhat gnu
|
ubuntu_linux enterprise_linux enterprise_virtualization glibc
|
The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SP…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3406
|
2024-11-21 10:40 |
2014-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291025
|
- |
|
canonical redhat gnu
|
ubuntu_linux enterprise_linux glibc enterprise_virtualization
|
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to …
|
CWE-189
Numeric Errors
|
CVE-2012-3405
|
2024-11-21 10:40 |
2014-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291026
|
- |
|
canonical redhat gnu
|
ubuntu_linux enterprise_linux enterprise_virtualization glibc
|
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to …
|
CWE-189
Numeric Errors
|
CVE-2012-3404
|
2024-11-21 10:40 |
2014-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291027
|
- |
|
redhat
|
jboss_enterprise_application_platform
|
EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3427
|
2024-11-21 10:40 |
2014-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291028
|
- |
|
f5
|
big-ip_webaccelerator big-ip_global_traffic_manager big-ip_local_traffic_manager big-ip_protocol_security_module big-ip_wan_optimization_manager big-ip_link_controller big-ip_analyt…
|
Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, PSM, APM, Edge Gateway, and Analytics and (2) AVR W…
|
CWE-89
SQL Injection
|
CVE-2012-3000
|
2024-11-21 10:40 |
2014-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291029
|
- |
|
f5
|
big-ip_configuration_utility
|
XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows remote authenticated users to read arbitrary files …
|
CWE-200
Information Exposure
|
CVE-2012-2997
|
2024-11-21 10:40 |
2014-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291030
|
- |
|
cisco
|
scientific_atlanta_wag310g scientific_atlanta_epc2420 scientific_atlanta_dpw700 scientific_atlanta_dpx100\/120 scientific_atlanta_dpc3008\/epc3008 scientific_atlanta_dpc\/epc2100 sc…
|
Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable modems allows remote attackers to inject arbitrary web script or HTML via unspecifi…
|
CWE-79
Cross-site Scripting
|
CVE-2012-3047
|
2024-11-21 10:40 |
2013-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|