Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 396 015

Количество 396 015

nvd логотип

CVE-2012-4527

почти 14 лет назад

Stack-based buffer overflow in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name. NOTE: it is not clear whether this is a vulnerability.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-4526

почти 7 лет назад

piwigo has XSS in password.php (incomplete fix for CVE-2012-4525)

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2012-4525

почти 7 лет назад

piwigo has XSS in password.php

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2012-4524

почти 7 лет назад

xlockmore before 5.43 'dclock' security bypass vulnerability

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-4523

почти 14 лет назад

radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2012-4522

почти 14 лет назад

The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-4521

почти 14 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4505. Reason: This candidate is a duplicate of CVE-2012-4505. Notes: All CVE users should reference CVE-2012-4505 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2012-4520

почти 14 лет назад

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2012-4519

больше 6 лет назад

Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2012-4518

почти 14 лет назад

ibacm 1.0.7 creates files with world-writable permissions, which allows local users to overwrite the ib_acm daemon log or ibacm.port file.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2012-4517

почти 14 лет назад

ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to cause a denial of service (ibacm service crash) via a crafted join response.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-4516

почти 14 лет назад

librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the address resolution information for the application via a malicious ib_acm service.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2012-4515

почти 14 лет назад

Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being updated.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-4514

почти 14 лет назад

rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-4513

почти 14 лет назад

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.

CVSS2: 6.4
EPSS: Средний
nvd логотип

CVE-2012-4512

больше 6 лет назад

The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."

CVSS3: 8.8
EPSS: Средний
nvd логотип

CVE-2012-4511

почти 14 лет назад

services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, which might allow remote attackers to obtain sensitive information via a man-in-the-middle (MITM) attack.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2012-4510

почти 14 лет назад

cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2012-4509

около 5 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

EPSS: Низкий
nvd логотип

CVE-2012-4508

почти 14 лет назад

Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.

CVSS2: 1.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2012-4527

Stack-based buffer overflow in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name. NOTE: it is not clear whether this is a vulnerability.

CVSS2: 6.8
8%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4526

piwigo has XSS in password.php (incomplete fix for CVE-2012-4525)

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-4525

piwigo has XSS in password.php

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-4524

xlockmore before 5.43 'dclock' security bypass vulnerability

CVSS3: 7.5
3%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-4523

radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients.

CVSS2: 6.4
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4522

The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.

CVSS2: 5
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4521

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4505. Reason: This candidate is a duplicate of CVE-2012-4505. Notes: All CVE users should reference CVE-2012-4505 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

почти 14 лет назад
nvd логотип
CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 6.4
4%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4519

Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2012-4518

ibacm 1.0.7 creates files with world-writable permissions, which allows local users to overwrite the ib_acm daemon log or ibacm.port file.

CVSS2: 3.6
0%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4517

ibacm before 1.0.6 does not properly manage reference counts for multicast connections, which allows remote attackers to cause a denial of service (ibacm service crash) via a crafted join response.

CVSS2: 5
3%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4516

librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the address resolution information for the application via a malicious ib_acm service.

CVSS2: 5.8
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4515

Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being updated.

CVSS2: 6.8
6%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4514

rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."

CVSS2: 5
10%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4513

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.

CVSS2: 6.4
13%
Средний
почти 14 лет назад
nvd логотип
CVE-2012-4512

The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."

CVSS3: 8.8
12%
Средний
больше 6 лет назад
nvd логотип
CVE-2012-4511

services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set, which might allow remote attackers to obtain sensitive information via a man-in-the-middle (MITM) attack.

CVSS2: 5.8
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4510

cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources.

CVSS2: 5.8
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4509

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

около 5 лет назад
nvd логотип
CVE-2012-4508

Race condition in fs/ext4/extents.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from a deleted file by reading an extent that was not properly marked as uninitialized.

CVSS2: 1.9
0%
Низкий
почти 14 лет назад

Уязвимостей на страницу