|
294341
|
6.1 |
MEDIUM
Network
|
atmail
|
atmail
|
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote attackers to inject arbitrary web script or HTML via the Date field of an email.
|
CWE-79
Cross-site Scripting
|
CVE-2012-2593
|
2024-11-21 10:39 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294342
|
7.2 |
HIGH
Network
|
tinywebgallery
|
tinywebgallery
|
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.
|
CWE-74
Injection
|
CVE-2012-2931
|
2024-11-21 10:39 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294343
|
5.3 |
MEDIUM
Network
|
md-systems
|
simplenews
|
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is…
|
CWE-200
Information Exposure
|
CVE-2012-2724
|
2024-11-21 10:39 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294344
|
9.8 |
CRITICAL
Network
|
browserid_project
|
browserid
|
The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier.
|
CWE-287
Improper Authentication
|
CVE-2012-2714
|
2024-11-21 10:39 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294345
|
4.4 |
MEDIUM
Local
|
gnome debian canonical opensuse
|
networkmanager debian_linux ubuntu_linux opensuse
|
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2012-2736
|
2024-11-21 10:39 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294346
|
7.5 |
HIGH
Network
|
talend
|
restlet
|
An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.
|
CWE-611
XXE
|
CVE-2012-2656
|
2024-11-21 10:39 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294347
|
9.8 |
CRITICAL
Network
|
solarwinds
|
backup_profiler storage_profiler storage_manager
|
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote at…
|
CWE-89
SQL Injection
|
CVE-2012-2576
|
2024-11-21 10:39 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294348
|
7.5 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
Unspecified vulnerability in FFMPEG 0.10 allows remote attackers to cause a denial of service.
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2012-2805
|
2024-11-21 10:39 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294349
|
9.8 |
CRITICAL
Network
|
ffmpeg
|
ffmpeg
|
Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2780.
|
NVD-CWE-noinfo
|
CVE-2012-2781
|
2024-11-21 10:39 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294350
|
9.8 |
CRITICAL
Network
|
ffmpeg
|
ffmpeg
|
Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2781.
|
NVD-CWE-noinfo
|
CVE-2012-2780
|
2024-11-21 10:39 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|