|
290381
|
7.5 |
HIGH
Network
|
phusion redhat
|
passenger openshift
|
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
|
CWE-20
Improper Input Validation
|
CVE-2012-6135
|
2024-11-21 10:45 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290382
|
7.5 |
HIGH
Network
|
nusoap_project debian
|
nusoap debian_linux
|
nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.
|
CWE-295
Improper Certificate Validation
|
CVE-2012-6071
|
2024-11-21 10:45 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290383
|
7.5 |
HIGH
Network
|
falconpl
|
falconpl
|
Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks.
|
CWE-20
Improper Input Validation
|
CVE-2012-6070
|
2024-11-21 10:45 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290384
|
9.8 |
CRITICAL
Network
|
call-cc
|
chicken
|
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
|
CWE-20
Improper Input Validation
|
CVE-2012-6125
|
2024-11-21 10:45 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290385
|
5.3 |
MEDIUM
Network
|
call-cc
|
chicken
|
A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2012-6124
|
2024-11-21 10:45 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290386
|
6.5 |
MEDIUM
Network
|
call-cc debian
|
chicken debian_linux
|
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
|
CWE-20
Improper Input Validation
|
CVE-2012-6123
|
2024-11-21 10:45 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290387
|
7.5 |
HIGH
Network
|
call-cc
|
chicken
|
Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.
|
CWE-120
Classic Buffer Overflow
|
CVE-2012-6122
|
2024-11-21 10:45 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290388
|
4.4 |
MEDIUM
Local
|
gofer_project
|
gofer
|
gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries.
|
CWE-275
Permission Issues
|
CVE-2012-5628
|
2024-11-21 10:45 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290389
|
6.1 |
MEDIUM
Network
|
apache
|
wicket
|
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vector…
|
CWE-79
Cross-site Scripting
|
CVE-2012-5636
|
2024-11-21 10:45 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290390
|
- |
|
clip-bucket
|
clipbucket
|
Multiple SQL injection vulnerabilities in ClipBucket 2.6 Revision 738 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in an add_friend action to ajax.ph…
|
CWE-89
SQL Injection
|
CVE-2012-5849
|
2024-11-21 10:45 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|