|
291751
|
9.8 |
CRITICAL
Network
|
invisioncommunity
|
invision_power_board
|
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2012-2226
|
2024-11-21 10:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291752
|
7.8 |
HIGH
Local
|
freedesktop xpdfreader redhat opensuse
|
poppler xpdf enterprise_linux opensuse
|
The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.
|
NVD-CWE-Other
|
CVE-2012-2142
|
2024-11-21 10:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291753
|
6.1 |
MEDIUM
Network
|
codeigniter
|
codeigniter
|
EllisLab CodeIgniter 2.1.2 allows remote attackers to bypass the xss_clean() Filter and perform XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2012-1915
|
2024-11-21 10:38 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291754
|
7.8 |
HIGH
Local
|
redhat
|
jboss_enterprise_application_platform jboss_application_server
|
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retain…
|
CWE-269
Improper Privilege Management
|
CVE-2012-2312
|
2024-11-21 10:38 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291755
|
6.1 |
MEDIUM
Network
|
mahara debian
|
mahara debian_linux
|
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javasc…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2237
|
2024-11-21 10:38 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291756
|
3.3 |
LOW
Local
|
redhat
|
jboss_community_application_server jboss_enterprise_web_server
|
An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
|
CWE-269
Improper Privilege Management
|
CVE-2012-2148
|
2024-11-21 10:38 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291757
|
7.4 |
HIGH
Network
|
polarssl debian fedoraproject
|
polarssl debian_linux fedora
|
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2012-2130
|
2024-11-21 10:38 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291758
|
5.9 |
MEDIUM
Network
|
canonical
|
ubuntu_cobbler
|
A Security Bypass vulnerability exists in Ubuntu Cobbler before 2,2,2 in the cobbler-ubuntu-import script due to an error when verifying the GPG signature.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2012-2092
|
2024-11-21 10:38 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291759
|
8.1 |
HIGH
Network
|
dhclient_project debian
|
dhclient debian_linux
|
An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
|
CWE-20
Improper Input Validation
|
CVE-2012-2248
|
2024-11-21 10:38 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291760
|
8.8 |
HIGH
Network
|
drupal
|
activity
|
A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.
|
CWE-352
Origin Validation Error
|
CVE-2012-2079
|
2024-11-21 10:38 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|