|
290301
|
- |
|
geopainting
|
gpsmapedit
|
GPSMapEdit 1.1.73.2 allows user-assisted remote attackers to cause a denial of service (crash) via a long string in a lst file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-6042
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290302
|
- |
|
morequick
|
greenbrowser
|
Double free vulnerability in GreenBrowser before 6.0.1002, when the keyword search bar (F6) is activated, allows remote attackers to execute arbitrary code via a crafted iframe.
|
CWE-399
Resource Management Errors
|
CVE-2012-6041
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290303
|
- |
|
convergine
|
file_king_advanced_file_management
|
Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6040
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290304
|
- |
|
yabsoft
|
advanced_image_hosting_script
|
SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows remote attackers to execute arbitrary SQL commands via the gal parameter.
|
CWE-89
SQL Injection
|
CVE-2012-6039
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290305
|
- |
|
razorcms
|
razorcms
|
admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, mov…
|
CWE-22
Path Traversal
|
CVE-2012-6038
|
2024-11-21 10:45 |
2012-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290306
|
- |
|
mahara
|
mahara
|
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6037
|
2024-11-21 10:45 |
2012-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290307
|
- |
|
xen
|
xen
|
The (1) memc_save_get_next_page, (2) tmemc_restore_put_page and (3) tmemc_restore_flush_page functions in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 do not check for negative id pools, w…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6036
|
2024-11-21 10:45 |
2012-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290308
|
- |
|
xen
|
xen
|
The do_tmem_destroy_pool function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 does not properly validate pool ids, which allows local guest OS users to cause a denial of service (memor…
|
CWE-20
Improper Input Validation
|
CVE-2012-6035
|
2024-11-21 10:45 |
2012-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290309
|
- |
|
xen
|
xen
|
The (1) tmemc_save_get_next_page and (2) tmemc_save_get_next_inv functions and the (3) TMEMC_SAVE_GET_POOL_UUID sub-operation in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 "do not check …
|
CWE-20
Improper Input Validation
|
CVE-2012-6034
|
2024-11-21 10:45 |
2012-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290310
|
- |
|
xen
|
xen
|
The do_tmem_control function in the Transcendent Memory (TMEM) in Xen 4.0, 4.1, and 4.2 does not properly check privileges, which allows local guest OS users to access control stack operations via un…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6033
|
2024-11-21 10:45 |
2012-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|