|
290451
|
7.5 |
HIGH
Network
|
gnome fedoraproject
|
gnome-system-log fedora
|
gnome-system-log polkit policy allows arbitrary files on the system to be read
|
CWE-200
Information Exposure
|
CVE-2012-5535
|
2024-11-21 10:44 |
2019-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290452
|
5.5 |
MEDIUM
Local
|
claws-mail
|
vcalendar
|
Claws Mail vCalendar plugin: credentials exposed on interface
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2012-5527
|
2024-11-21 10:44 |
2019-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290453
|
6.5 |
MEDIUM
Adjacent
|
quagga debian redhat
|
quagga debian_linux enterprise_linux
|
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
|
CWE-617
Reachable Assertion
|
CVE-2012-5521
|
2024-11-21 10:44 |
2019-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290454
|
7.5 |
HIGH
Network
|
ovirt
|
vdsm
|
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
|
CWE-295
Improper Certificate Validation
|
CVE-2012-5518
|
2024-11-21 10:44 |
2019-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290455
|
6.2 |
MEDIUM
Local
|
python
|
keyring
|
Python keyring has insecure permissions on new databases allowing world-readable files to be created
|
CWE-276
Incorrect Default Permissions
|
CVE-2012-5578
|
2024-11-21 10:44 |
2019-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290456
|
6.1 |
MEDIUM
Network
|
bitweaver
|
bitweaver
|
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the path info to (1) stats/index.php or (2) newsle…
|
CWE-79
Cross-site Scripting
|
CVE-2012-5193
|
2024-11-21 10:44 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290457
|
7.5 |
HIGH
Network
|
python debian
|
keyring debian_linux
|
Python keyring lib before 0.10 created keyring files with world-readable permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2012-5577
|
2024-11-21 10:44 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290458
|
8.8 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted QT file.
|
CWE-20
Improper Input Validation
|
CVE-2012-5360
|
2024-11-21 10:44 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290459
|
8.8 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted ASF file.
|
CWE-20
Improper Input Validation
|
CVE-2012-5359
|
2024-11-21 10:44 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290460
|
9.8 |
CRITICAL
Network
|
ektron
|
ektron_content_management_system
|
The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with enableDocumentFunction set to true, which allows remote attackers to read arbitrar…
|
CWE-19
Data Processing Errors
|
CVE-2012-5358
|
2024-11-21 10:44 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|