|
290771
|
7.5 |
HIGH
Network
|
ovirt
|
vdsm
|
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
|
CWE-295
Improper Certificate Validation
|
CVE-2012-5518
|
2024-11-21 10:44 |
2019-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290772
|
6.2 |
MEDIUM
Local
|
python
|
keyring
|
Python keyring has insecure permissions on new databases allowing world-readable files to be created
|
CWE-276
Incorrect Default Permissions
|
CVE-2012-5578
|
2024-11-21 10:44 |
2019-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290773
|
6.1 |
MEDIUM
Network
|
bitweaver
|
bitweaver
|
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsle…
|
CWE-79
Cross-site Scripting
|
CVE-2012-5193
|
2024-11-21 10:44 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290774
|
7.5 |
HIGH
Network
|
python debian
|
keyring debian_linux
|
Python keyring lib before 0.10 created keyring files with world-readable permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2012-5577
|
2024-11-21 10:44 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290775
|
8.8 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted QT file.
|
CWE-20
Improper Input Validation
|
CVE-2012-5360
|
2024-11-21 10:44 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290776
|
8.8 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted ASF file.
|
CWE-20
Improper Input Validation
|
CVE-2012-5359
|
2024-11-21 10:44 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290777
|
9.8 |
CRITICAL
Network
|
ektron
|
ektron_content_management_system
|
The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with enableDocumentFunction set to true, which allows remote attackers to read arbitrar…
|
CWE-19
Data Processing Errors
|
CVE-2012-5358
|
2024-11-21 10:44 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290778
|
9.8 |
CRITICAL
Network
|
ektron
|
ektron_content_management_system
|
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE …
|
CWE-19
Data Processing Errors
|
CVE-2012-5357
|
2024-11-21 10:44 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290779
|
7.8 |
HIGH
Local
|
ffmpeg
|
ffmpeg
|
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted WMV file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-5361
|
2024-11-21 10:44 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290780
|
- |
|
tvmobili
|
tvmobili
|
Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before 2.1.0.3974 allow remote attackers to cause a denial of service (tvMobiliService service crash) via a long string in a (1) GET…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-5451
|
2024-11-21 10:44 |
2015-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|