|
291931
|
- |
|
mnt-tech
|
wp-facethumb
|
Cross-site scripting (XSS) vulnerability in index.php in the WP-FaceThumb plugin 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pagination_wp_facethumb param…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2371
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291932
|
- |
|
gnome
|
gdk-pixbuf
|
Multiple integer overflows in the read_bitmap_file_data function in io-xbm.c in gdk-pixbuf before 2.26.1 allow remote attackers to cause a denial of service (application crash) via a negative (1) hei…
|
CWE-189
Numeric Errors
|
CVE-2012-2370
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291933
|
- |
|
bytemark
|
symbiosis
|
Bytemark Symbiosis before Revision 1322 does not properly validate passwords, which allows remote attackers to gain access to email accounts via an arbitrary password.
|
CWE-20
Improper Input Validation
|
CVE-2012-2368
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291934
|
- |
|
mybb
|
mybb
|
MyBB (aka MyBulletinBoard) before 1.6.7 allows remote attackers to obtain sensitive information via a malformed forumread cookie, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2012-2327
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291935
|
- |
|
mybb
|
mybb
|
Cross-site scripting (XSS) vulnerability in the Admin Control Panel (ACP) in MyBB (aka MyBulletinBoard) before 1.6.7 allows remote administrators to inject arbitrary web script or HTML via a malforme…
|
CWE-79
Cross-site Scripting
|
CVE-2012-2326
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291936
|
- |
|
mybb
|
mybb
|
SQL injection vulnerability in the User Inline Moderation feature in the Admin Control Panel (ACP) in MyBB (aka MyBulletinBoard) before 1.6.7 allows remote administrators to execute arbitrary SQL com…
|
CWE-89
SQL Injection
|
CVE-2012-2325
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291937
|
- |
|
mybb
|
mybb
|
Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.7 allow remote administrators to execute arbitrary SQL commands via unspecified vectors in the (1) user search or (2) M…
|
CWE-89
SQL Injection
|
CVE-2012-2324
|
2024-11-21 10:38 |
2012-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291938
|
- |
|
linux
|
linux_kernel
|
The Linux kernel before 3.4.5 on the x86 platform, when Physical Address Extension (PAE) is enabled, does not properly use the Page Middle Directory (PMD), which allows local users to cause a denial …
|
CWE-362
Race Condition
|
CVE-2012-2373
|
2024-11-21 10:38 |
2012-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291939
|
- |
|
linux
|
linux_kernel
|
The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-ba…
|
CWE-20
Improper Input Validation
|
CVE-2012-2136
|
2024-11-21 10:38 |
2012-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291940
|
- |
|
ibm
|
rational_directory_server tivoli_directory_server global_security_kit
|
IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses the PKCS #12 file format for certificate objects …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2203
|
2024-11-21 10:38 |
2012-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|