|
292441
|
- |
|
dotcms
|
dotcms
|
dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1826
|
2024-11-21 10:37 |
2012-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292442
|
6.5 |
MEDIUM
Network
|
imagemagick debian redhat opensuse
|
imagemagick debian_linux enterprise_linux_server_aus enterprise_linux_desktop enterprise_linux_server_eus enterprise_linux_server enterprise_linux_workstation storage enterpri…
|
The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted EXIF IFD in a TIFF …
|
CWE-125
Out-of-bounds Read
|
CVE-2012-1798
|
2024-11-21 10:37 |
2012-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292443
|
7.5 |
HIGH
Network
|
imagemagick debian canonical opensuse
|
imagemagick debian_linux ubuntu_linux opensuse
|
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component cou…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2012-1610
|
2024-11-21 10:37 |
2012-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292444
|
- |
|
isc
|
bind
|
ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, wh…
|
CWE-189
Numeric Errors
|
CVE-2012-1667
|
2024-11-21 10:37 |
2012-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292445
|
- |
|
oscommerce
|
online_merchant
|
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in OSCommerce Online Merchant 3.0.2, when the software is being installed, allows remote …
|
CWE-79
Cross-site Scripting
|
CVE-2012-1792
|
2024-11-21 10:37 |
2012-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292446
|
- |
|
measuresoft
|
scadapro_client scadapro_server
|
Untrusted search path vulnerability in Measuresoft ScadaPro Client before 4.0.0 and ScadaPro Server before 4.0.0 allows local users to gain privileges via a Trojan horse DLL in the current working di…
|
NVD-CWE-Other
|
CVE-2012-1824
|
2024-11-21 10:37 |
2012-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292447
|
- |
|
symantec
|
endpoint_protection
|
The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.700x on Windows Server 2003 allows remote attackers to cause a denial of ser…
|
NVD-CWE-Other
|
CVE-2012-1821
|
2024-11-21 10:37 |
2012-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292448
|
- |
|
drupal
|
drupal
|
Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destina…
|
CWE-20
Improper Input Validation
|
CVE-2012-1589
|
2024-11-21 10:37 |
2012-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292449
|
- |
|
linux
|
linux_kernel
|
The KVM implementation in the Linux kernel before 3.3.6 allows host OS users to cause a denial of service (NULL pointer dereference and host OS crash) by making a KVM_CREATE_IRQCHIP ioctl call after …
|
CWE-399
Resource Management Errors
|
CVE-2012-1601
|
2024-11-21 10:37 |
2012-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292450
|
- |
|
progea
|
movicon
|
The OPC server in Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-1804
|
2024-11-21 10:37 |
2012-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|