|
291851
|
- |
|
eucalyptus
|
eucalyptus
|
Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to bypass unspecified authorization checks and obtain di…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4065
|
2024-11-21 10:42 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291852
|
- |
|
eucalyptus
|
eucalyptus
|
Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to gain privileges by sending a message to (1) Cloud Con…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4064
|
2024-11-21 10:42 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291853
|
- |
|
eucalyptus
|
eucalyptus
|
The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows remote attackers to cause a denial of service via…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4063
|
2024-11-21 10:42 |
2012-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291854
|
- |
|
fedoraproject
|
389_directory_server
|
389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restriction…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4450
|
2024-11-21 10:42 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291855
|
- |
|
smarty
|
smarty
|
Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors t…
|
CWE-79
Cross-site Scripting
|
CVE-2012-4437
|
2024-11-21 10:42 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291856
|
- |
|
optipng
|
optipng
|
Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction."
|
CWE-399
Resource Management Errors
|
CVE-2012-4432
|
2024-11-21 10:42 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291857
|
- |
|
gnome
|
gnome-shell
|
The gnome-shell plugin 3.4.1 in GNOME allows remote attackers to force the download and installation of arbitrary extensions from extensions.gnome.org via a crafted web page.
|
CWE-94
Code Injection
|
CVE-2012-4427
|
2024-11-21 10:42 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291858
|
- |
|
fedoraproject guac-dev
|
fedora guacamole
|
Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a l…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-4415
|
2024-11-21 10:42 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291859
|
- |
|
david_king
|
vino
|
Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.
|
CWE-200
Information Exposure
|
CVE-2012-4429
|
2024-11-21 10:42 |
2012-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291860
|
- |
|
wordpress
|
wordpress
|
Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via…
|
CWE-352
Origin Validation Error
|
CVE-2012-4448
|
2024-11-21 10:42 |
2012-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|