|
291081
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
The Inter-process Communication (IPC) implementation in Google Chrome before 22.0.1229.94 allows remote attackers to bypass intended sandbox restrictions and write to arbitrary files by leveraging ac…
|
CWE-269
Improper Privilege Management
|
CVE-2012-5376
|
2024-11-21 10:44 |
2012-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291082
|
- |
|
google apple
|
chrome iphone_os
|
Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22.0.1229.94, allows remote attackers to execute arbitrary code via unspecified vectors.
|
CWE-399
Resource Management Errors
|
CVE-2012-5112
|
2024-11-21 10:44 |
2012-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291083
|
- |
|
isc
|
bind
|
ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via u…
|
CWE-189
Numeric Errors
|
CVE-2012-5166
|
2024-11-21 10:44 |
2012-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291084
|
- |
|
canonical
|
ubuntu_software_properties
|
The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before 0.81.13.5, 0.82.x before 0.82.7.3, and 0.92.x before 0.92.8 does not properly …
|
CWE-20
Improper Input Validation
|
CVE-2012-5356
|
2024-11-21 10:44 |
2012-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291085
|
- |
|
bryce_harrington
|
xdiagnose
|
welcome.py in xdiagnose before 2.5.2ubuntu0.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
|
CWE-59
Link Following
|
CVE-2012-5355
|
2024-11-21 10:44 |
2012-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291086
|
- |
|
mozilla
|
firefox thunderbird seamonkey
|
Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly handle navigation away from a web page that has multiple menus of SELECT elements active, which allows …
|
NVD-CWE-Other
|
CVE-2012-5354
|
2024-11-21 10:44 |
2012-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291087
|
- |
|
eduserv
|
openathens_service_provider
|
Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."
|
CWE-287
Improper Authentication
|
CVE-2012-5353
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291088
|
- |
|
josso
|
java_open_single_sign-on_project_home
|
Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attac…
|
CWE-287
Improper Authentication
|
CVE-2012-5352
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291089
|
- |
|
apache
|
axis2
|
Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a different vulnerability tha…
|
CWE-287
Improper Authentication
|
CVE-2012-5351
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291090
|
- |
|
wordpress
|
pay-with-tweet
|
SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with certain permissions to execute arbitrary SQL commands via the id parameter in …
|
CWE-89
SQL Injection
|
CVE-2012-5350
|
2024-11-21 10:44 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|