|
291801
|
5.5 |
MEDIUM
Local
|
redhat fedoraproject debian
|
tuned fedora enterprise_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
|
CWE-276
Incorrect Default Permissions
|
CVE-2012-6136
|
2024-11-21 10:45 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291802
|
7.5 |
HIGH
Network
|
phusion redhat
|
passenger openshift
|
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
|
CWE-20
Improper Input Validation
|
CVE-2012-6135
|
2024-11-21 10:45 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291803
|
7.5 |
HIGH
Network
|
nusoap_project debian
|
nusoap debian_linux
|
nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.
|
CWE-295
Improper Certificate Validation
|
CVE-2012-6071
|
2024-11-21 10:45 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291804
|
7.5 |
HIGH
Network
|
falconpl
|
falconpl
|
Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks.
|
CWE-20
Improper Input Validation
|
CVE-2012-6070
|
2024-11-21 10:45 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291805
|
9.8 |
CRITICAL
Network
|
call-cc
|
chicken
|
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
|
CWE-20
Improper Input Validation
|
CVE-2012-6125
|
2024-11-21 10:45 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291806
|
5.3 |
MEDIUM
Network
|
call-cc
|
chicken
|
A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2012-6124
|
2024-11-21 10:45 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291807
|
6.5 |
MEDIUM
Network
|
call-cc debian
|
chicken debian_linux
|
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
|
CWE-20
Improper Input Validation
|
CVE-2012-6123
|
2024-11-21 10:45 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291808
|
7.5 |
HIGH
Network
|
call-cc
|
chicken
|
Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.
|
CWE-120
Classic Buffer Overflow
|
CVE-2012-6122
|
2024-11-21 10:45 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291809
|
4.4 |
MEDIUM
Local
|
gofer_project
|
gofer
|
gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries.
|
CWE-275
Permission Issues
|
CVE-2012-5628
|
2024-11-21 10:45 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291810
|
6.1 |
MEDIUM
Network
|
apache
|
wicket
|
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.22, 1.5.x before 1.5.10, and 6.x before 6.4.0 might allow remote attackers to inject arbitrary web script or HTML via vector…
|
CWE-79
Cross-site Scripting
|
CVE-2012-5636
|
2024-11-21 10:45 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|