|
294221
|
7.5 |
HIGH
Network
|
redhat
|
jboss_application_server
|
JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.
|
CWE-200
Information Exposure
|
CVE-2012-1094
|
2024-11-21 10:36 |
2020-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294222
|
7.8 |
HIGH
Local
|
debian
|
debian_linux x11-common
|
The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.
|
CWE-59
Link Following
|
CVE-2012-1093
|
2024-11-21 10:36 |
2020-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294223
|
7.8 |
HIGH
Local
|
nvidia
|
display_driver
|
A Memory Corruption Vulnerability exists in NVIDIA Graphics Drivers 29549 due to an unknown function in the file proc/driver/nvidia/registry.
|
CWE-787
Out-of-bounds Write
|
CVE-2012-0951
|
2024-11-21 10:36 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294224
|
9.8 |
CRITICAL
Network
|
phxeventmanager_project
|
phxeventmanager
|
SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.
|
CWE-89
SQL Injection
|
CVE-2012-1124
|
2024-11-21 10:36 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294225
|
7.4 |
HIGH
Network
|
cisco
|
ironport_web_security_appliance
|
Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead to MITM attacks
|
CWE-20
Improper Input Validation
|
CVE-2012-1326
|
2024-11-21 10:36 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294226
|
5.9 |
MEDIUM
Network
|
cisco
|
ironport_web_security_appliance
|
Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks
|
CWE-295
Improper Certificate Validation
|
CVE-2012-1316
|
2024-11-21 10:36 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294227
|
4.9 |
MEDIUM
Network
|
whoopsie-daisy_project
|
whoopsie-daisy
|
whoopsie-daisy before 0.1.26: Root user can remove arbitrary files
|
CWE-428
Unquoted Search Path or Element
|
CVE-2012-0945
|
2024-11-21 10:36 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294228
|
6.1 |
MEDIUM
Network
|
plixer
|
scrutinizer_netflow_\&_sflow_analyzer
|
Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow and sFlow Analyzer 8.6.2.16204 and other versions before 9.0.1.19899 allows rem…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1261
|
2024-11-21 10:36 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294229
|
6.1 |
MEDIUM
Network
|
plixer
|
scrutinizer_netflow_\&_sflow_analyzer
|
Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allows remo…
|
CWE-79
Cross-site Scripting
|
CVE-2012-1260
|
2024-11-21 10:36 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294230
|
9.8 |
CRITICAL
Network
|
plixer
|
scrutinizer_netflow_\&_sflow_analyzer
|
Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbi…
|
CWE-89
SQL Injection
|
CVE-2012-1259
|
2024-11-21 10:36 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|