|
290911
|
- |
|
m2osw
|
tableofcontents
|
The Table of Contents module 6.x-3.x before 6.x-3.8 for Drupal does not properly check node permissions, which allows remote attackers to read a node's headers by accessing a table of contents block.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5584
|
2024-11-21 10:44 |
2012-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290912
|
- |
|
naver
|
loctouch
|
The Loctouch application 3.4.6 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log …
|
CWE-200
Information Exposure
|
CVE-2012-5183
|
2024-11-21 10:44 |
2012-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290913
|
- |
|
naver
|
loctouch
|
The Loctouch application 3.4.6 and earlier for Android does not properly handle implicit intents, which allows attackers to obtain sensitive information about logged locations via a crafted applicati…
|
CWE-200
Information Exposure
|
CVE-2012-5182
|
2024-11-21 10:44 |
2012-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290914
|
- |
|
opera
|
opera_mini opera_mobile
|
The Opera Mobile application before 12.1 and Opera Mini application before 7.5 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a cr…
|
CWE-200
Information Exposure
|
CVE-2012-5180
|
2024-11-21 10:44 |
2012-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290915
|
- |
|
boatmob
|
boat_browser boat_browser_mini
|
The Boat Browser application before 4.2 and Boat Browser Mini application before 3.9 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information vi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5179
|
2024-11-21 10:44 |
2012-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290916
|
- |
|
concrete5
|
concrete5
|
Cross-site scripting (XSS) vulnerability in concrete5 Japanese 5.5.1 through 5.5.2.1 and concrete5 English 5.5.0 through 5.6.0.2 allows remote attackers to inject arbitrary web script or HTML via uns…
|
CWE-79
Cross-site Scripting
|
CVE-2012-5181
|
2024-11-21 10:44 |
2012-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290917
|
- |
|
linux
|
linux_kernel
|
The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecifie…
|
NVD-CWE-Other
|
CVE-2012-5517
|
2024-11-21 10:44 |
2012-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290918
|
- |
|
phpmyadmin
|
phpmyadmin
|
The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a direct request to wp-content/plugins/portable-php…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5469
|
2024-11-21 10:44 |
2012-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290919
|
- |
|
welcart
|
welcart_plugin
|
Cross-site request forgery (CSRF) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that complete a p…
|
CWE-352
Origin Validation Error
|
CVE-2012-5178
|
2024-11-21 10:44 |
2012-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290920
|
- |
|
welcart
|
welcart_plugin
|
Cross-site scripting (XSS) vulnerability in the Welcart plugin before 1.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-5177
|
2024-11-21 10:44 |
2012-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|