|
289541
|
- |
|
ibm
|
lotus_notes_traveler
|
servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it easier for remote attackers to obtain access via …
|
CWE-287
Improper Authentication
|
CVE-2012-5309
|
2024-11-21 10:44 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289542
|
- |
|
ibm
|
lotus_notes_traveler
|
Cross-site request forgery (CSRF) vulnerability in servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 allows remote attackers to hijack the authentication of arbitrary users f…
|
CWE-352
Origin Validation Error
|
CVE-2012-5308
|
2024-11-21 10:44 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289543
|
- |
|
ibm
|
lotus_notes_traveler
|
Cross-site scripting (XSS) vulnerability in servlet/traveler in IBM Lotus Notes Traveler before 8.5.3.3 Interim Fix 1, when Firefox is used, allows remote attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2012-5307
|
2024-11-21 10:44 |
2012-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289544
|
- |
|
dlink
|
dcs-5605_ptz_ip_network_camera camera_stream_client_activex_control
|
Stack-based buffer overflow in the SelectDirectory method in DcsCliCtrl.dll in Camera Stream Client ActiveX Control, as used in D-Link DCS-5605 PTZ IP Network Camera, allows remote attackers to cause…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-5306
|
2024-11-21 10:44 |
2012-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289545
|
- |
|
directadmin
|
directadmin
|
Cross-site scripting (XSS) vulnerability in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allows remote attackers to inject arbitrary web script or HTML via the domain parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-5305
|
2024-11-21 10:44 |
2012-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289546
|
- |
|
yuriy_v_semenikhin
|
yvs_image_gallery
|
Static code injection vulnerability in administration/install.php in YVS Image Gallery allows remote attackers to inject arbitrary PHP code into functions/db_connect.php via unspecified vectors. NOT…
|
CWE-94
Code Injection
|
CVE-2012-5304
|
2024-11-21 10:44 |
2012-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289547
|
- |
|
monkey-project
|
monkey
|
Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from the default /var/run/monkey.pid pathname.
|
CWE-59
Link Following
|
CVE-2012-5303
|
2024-11-21 10:44 |
2012-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289548
|
- |
|
cerberusftp
|
ftp_server
|
The default configuration of Cerberus FTP Server before 5.0.4.0 supports the DES cipher for SSH sessions, which makes it easier for remote attackers to obtain sensitive information by sniffing the ne…
|
CWE-310
Cryptographic Issues
|
CVE-2012-5301
|
2024-11-21 10:44 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289549
|
- |
|
wireshark
|
wireshark
|
Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (application cras…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-5240
|
2024-11-21 10:44 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289550
|
- |
|
wireshark
|
wireshark
|
epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.3 uses incorrect OUI data structures during the decoding of (1) PPP and (2) LCP data, which allows remote attackers to …
|
NVD-CWE-noinfo
|
CVE-2012-5238
|
2024-11-21 10:44 |
2012-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|