|
288431
|
- |
|
google
|
android_api
|
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary methods of Java objects by using the Java Reflection…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6636
|
2024-11-21 10:46 |
2014-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288432
|
- |
|
linux
|
linux_kernel
|
The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (kernel resource consumption) via a flood of SYN+FIN …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2012-6638
|
2024-11-21 10:46 |
2014-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288433
|
- |
|
rapid7
|
nexpose
|
Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers to hijack the authentication of unspecified victims for requests that delete sc…
|
CWE-352
Origin Validation Error
|
CVE-2012-6493
|
2024-11-21 10:46 |
2014-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288434
|
- |
|
splunk
|
splunk
|
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 5.0.0 through 5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6447
|
2024-11-21 10:46 |
2014-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288435
|
- |
|
kernel
|
util-linux
|
(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line …
|
CWE-200
Information Exposure
|
CVE-2013-0157
|
2024-11-21 10:46 |
2014-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288436
|
- |
|
wordpress
|
wordpress
|
wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by vi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6635
|
2024-11-21 10:46 |
2014-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288437
|
- |
|
wordpress
|
wordpress
|
wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6634
|
2024-11-21 10:46 |
2014-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288438
|
- |
|
wordpress
|
wordpress
|
Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6633
|
2024-11-21 10:46 |
2014-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288439
|
- |
|
vessio
|
netbill
|
Multiple cross-site scripting (XSS) vulnerabilities in Vessio NetBill 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) file title to accounts/admin/index…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6632
|
2024-11-21 10:46 |
2014-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288440
|
- |
|
vessio
|
netbill
|
Cross-site request forgery (CSRF) vulnerability in accounts/admin/index.php in Vessio NetBill 1.2 allows remote attackers to hijack the authentication of administrators for requests that add accounts…
|
CWE-352
Origin Validation Error
|
CVE-2012-6631
|
2024-11-21 10:46 |
2014-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|