|
290821
|
- |
|
cisco
|
ios as5400_universal_gateway as5400hpx_universal_gateway as5400xm_media_gateway as5400xm_universal_gateway
|
Unspecified vulnerability in Cisco IOS before 15.3(2)T on AS5400 devices allows remote authenticated users to cause a denial of service (spurious errors) via unknown vectors, aka Bug ID CSCub61009.
|
NVD-CWE-noinfo
|
CVE-2012-5422
|
2024-11-21 10:44 |
2014-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290822
|
- |
|
horde
|
groupware kronolith_h4
|
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.18, as used in Horde Groupware Webmail Edition before 4.0.9, allow remote attackers to inject…
|
CWE-79
Cross-site Scripting
|
CVE-2012-5567
|
2024-11-21 10:44 |
2014-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290823
|
- |
|
horde
|
kronolith_h4 groupware
|
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.17, as used in Horde Groupware Webmail Edition before 4.0.8, allow remote attackers to inject…
|
CWE-79
Cross-site Scripting
|
CVE-2012-5566
|
2024-11-21 10:44 |
2014-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290824
|
- |
|
horde
|
imp groupware
|
Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Horde Internet Mail Program (IMP) before 5.0.24, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to …
|
CWE-79
Cross-site Scripting
|
CVE-2012-5565
|
2024-11-21 10:44 |
2014-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290825
|
- |
|
puppetlabs puppet
|
puppet puppet_enterprise
|
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2012-5158
|
2024-11-21 10:44 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290826
|
- |
|
gajim
|
gajim
|
The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which allows remote attackers to conduct man-in-the-middle (MITM) attacks and spoof se…
|
CWE-20
Improper Input Validation
|
CVE-2012-5524
|
2024-11-21 10:44 |
2014-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290827
|
- |
|
bitweaver
|
bitweaver
|
Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files via "''%2F" (dot dot encoded slash) sequences in the overlay_…
|
CWE-22
Path Traversal
|
CVE-2012-5192
|
2024-11-21 10:44 |
2014-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290828
|
- |
|
mediawiki
|
mediawiki
|
Cross-site request forgery (CSRF) vulnerability in the CentralAuth extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to hijack the authenti…
|
CWE-352
Origin Validation Error
|
CVE-2012-5394
|
2024-11-21 10:44 |
2013-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290829
|
- |
|
jforum
|
jforum
|
Open redirect vulnerability in JForum 2.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the returnPath parameter in a validateLogin acti…
|
CWE-20
Improper Input Validation
|
CVE-2012-5338
|
2024-11-21 10:44 |
2013-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290830
|
- |
|
apache redhat
|
cxf jboss_enterprise_web_platform jboss_enterprise_soa_platform jboss_fuse_esb_enterprise jboss_enterprise_portal_platform jboss_enterprise_application_platform
|
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definiti…
|
CWE-310
Cryptographic Issues
|
CVE-2012-5575
|
2024-11-21 10:44 |
2013-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|