Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 396 541

Количество 396 541

nvd логотип

CVE-2012-6136

почти 7 лет назад

tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-6135

почти 7 лет назад

RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-6134

больше 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the omniauth-oauth2 gem 1.1.1 and earlier for Ruby allows remote attackers to hijack the authentication of users for requests that modify session state.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-6133

больше 6 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2012-6132

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-6131

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-6130

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-6129

больше 13 лет назад

Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-6128

больше 13 лет назад

Multiple stack-based buffer overflows in http.c in OpenConnect before 4.08 allow remote VPN gateways to cause a denial of service (application crash) via a long (1) hostname, (2) path, or (3) cookie list in a response.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-6127

больше 13 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This was originally reported as an issue in jakarta-commons-httpclient involving wildcard matching in the SSL hostname verifier, but further investigation showed that it was not a security issue. Notes: none

EPSS: Низкий
nvd логотип

CVE-2012-6126

больше 13 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4525, CVE-2012-4526. Reason: This candidate is a duplicate of CVE-2012-4525 and CVE-2012-4526. Notes: All CVE users should reference CVE-2012-4525 and/or CVE-2012-4526 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2012-6125

почти 7 лет назад

Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2012-6124

почти 7 лет назад

A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)."

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2012-6123

почти 7 лет назад

Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2012-6122

почти 7 лет назад

Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-6121

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-6120

больше 13 лет назад

Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2012-6119

больше 13 лет назад

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2012-6118

больше 13 лет назад

The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instances quota user setting.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-6117

больше 13 лет назад

Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2012-6136

tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

CVSS3: 5.5
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-6135

RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

CVSS3: 7.5
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-6134

Cross-site request forgery (CSRF) vulnerability in the omniauth-oauth2 gem 1.1.1 and earlier for Ruby allows remote attackers to hijack the authentication of users for requests that modify session state.

CVSS2: 6.8
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-6133

Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary web script or HTML via the (1) @ok_message or (2) @error_message parameter to issue*.

CVSS3: 6.1
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2012-6132

Cross-site scripting (XSS) vulnerability in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the otk parameter.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-6131

Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-6130

Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-6129

Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets."

CVSS2: 7.5
5%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-6128

Multiple stack-based buffer overflows in http.c in OpenConnect before 4.08 allow remote VPN gateways to cause a denial of service (application crash) via a long (1) hostname, (2) path, or (3) cookie list in a response.

CVSS2: 5
3%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-6127

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This was originally reported as an issue in jakarta-commons-httpclient involving wildcard matching in the SSL hostname verifier, but further investigation showed that it was not a security issue. Notes: none

больше 13 лет назад
nvd логотип
CVE-2012-6126

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4525, CVE-2012-4526. Reason: This candidate is a duplicate of CVE-2012-4525 and CVE-2012-4526. Notes: All CVE users should reference CVE-2012-4525 and/or CVE-2012-4526 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

больше 13 лет назад
nvd логотип
CVE-2012-6125

Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.

CVSS3: 9.8
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-6124

A casting error in Chicken before 4.8.0 on 64-bit platform caused the random number generator to return a constant value. NOTE: the vendor states "This function wasn't used for security purposes (and is advertised as being unsuitable)."

CVSS3: 5.3
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-6123

Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."

CVSS3: 6.5
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-6122

Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value.

CVSS3: 7.5
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-6121

Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.8.5 allows remote attackers to inject arbitrary web script or HTML via a (1) data:text or (2) vbscript link.

CVSS2: 4.3
2%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-6120

Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-6119

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-6118

The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instances quota user setting.

CVSS2: 5.5
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-6117

Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад

Уязвимостей на страницу