|
290811
|
- |
|
freefloat
|
freefloat_ftp_server
|
Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via a long string in a PUT command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-5106
|
2024-11-21 10:44 |
2014-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290812
|
- |
|
apereo
|
phpcas
|
phpCAS before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle a…
|
CWE-310
Cryptographic Issues
|
CVE-2012-5583
|
2024-11-21 10:44 |
2014-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290813
|
- |
|
condor_project
|
condor
|
The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privil…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5390
|
2024-11-21 10:44 |
2014-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290814
|
- |
|
owncloud
|
owncloud
|
lib/base.php in ownCloud before 4.0.8 does not properly validate the user_id session variable, which allows remote authenticated users to read arbitrary files via vectors related to WebDAV.
|
CWE-20
Improper Input Validation
|
CVE-2012-5336
|
2024-11-21 10:44 |
2014-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290815
|
- |
|
mediawiki
|
mediawiki
|
Session fixation vulnerability in the CentralAuth extension for MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the centrala…
|
NVD-CWE-Other
|
CVE-2012-5395
|
2024-11-21 10:44 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290816
|
- |
|
mediawiki
|
mediawiki
|
Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.
|
NVD-CWE-Other
|
CVE-2012-5391
|
2024-11-21 10:44 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290817
|
- |
|
dancer
|
dancer
|
CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks v…
|
CWE-20
Improper Input Validation
|
CVE-2012-5572
|
2024-11-21 10:44 |
2014-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290818
|
- |
|
mate-desktop
|
mate-settings-daemon
|
The default configuration in mate-settings-daemon 1.5.3 allows local users to change the timezone for the system via a crafted D-Bus call.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5560
|
2024-11-21 10:44 |
2014-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290819
|
- |
|
theforeman
|
foreman
|
The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5477
|
2024-11-21 10:44 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290820
|
- |
|
cisco
|
ios
|
Cisco IOS Unified Border Element (CUBE) in Cisco IOS before 15.3(2)T allows remote authenticated users to cause a denial of service (input queue wedge) via a crafted series of RTCP packets, aka Bug I…
|
CWE-20
Improper Input Validation
|
CVE-2012-5427
|
2024-11-21 10:44 |
2014-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|