|
294641
|
- |
|
redhat augeas
|
enterprise_linux augeas
|
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files a…
|
NVD-CWE-noinfo
|
CVE-2012-0787
|
2024-11-21 10:35 |
2013-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294642
|
- |
|
augeas
|
augeas
|
The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augnew file.
|
CWE-59
Link Following
|
CVE-2012-0786
|
2024-11-21 10:35 |
2013-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294643
|
- |
|
drupal
|
drupal
|
The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields vi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-0827
|
2024-11-21 10:35 |
2013-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294644
|
- |
|
drupal
|
drupal
|
Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for …
|
CWE-352
Origin Validation Error
|
CVE-2012-0826
|
2024-11-21 10:35 |
2013-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294645
|
- |
|
drupal
|
drupal
|
Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without det…
|
CWE-200
Information Exposure
|
CVE-2012-0825
|
2024-11-21 10:35 |
2013-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294646
|
- |
|
gnu
|
glibc
|
Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct for…
|
CWE-189
Numeric Errors
|
CVE-2012-0864
|
2024-11-21 10:35 |
2013-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294647
|
- |
|
sun
|
sunos
|
Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11 allows local users to affect availability via unknown vectors related to Libraries/Libc.
|
NVD-CWE-noinfo
|
CVE-2012-0570
|
2024-11-21 10:35 |
2013-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294648
|
- |
|
sun
|
sunos
|
Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows local users to affect confidentiality via unknown vectors related to Utility/fdformat.
|
NVD-CWE-noinfo
|
CVE-2012-0568
|
2024-11-21 10:35 |
2013-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294649
|
- |
|
ibm
|
scale_out_network_attached_storage
|
IBM Scale Out Network Attached Storage (SONAS) 1.3 before 1.3.2.3 requires cleartext storage of LDAP credentials without recommending a less privileged LDAP account, which might allow attackers to ob…
|
CWE-255 CWE-264
Credentials Management Permissions, Privileges, and Access Controls
|
CVE-2012-0706
|
2024-11-21 10:35 |
2013-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294650
|
- |
|
oracle mysql
|
mysql
|
Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a different vulnerability than CVE-2013-1492.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-0553
|
2024-11-21 10:35 |
2013-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|