Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 396 015

Количество 396 015

nvd логотип

CVE-2012-4447

почти 14 лет назад

Heap-based buffer overflow in tif_pixarlog.c in LibTIFF before 4.0.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF image using the PixarLog Compression format.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-4446

больше 13 лет назад

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-4445

почти 14 лет назад

Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-4444

почти 14 лет назад

The ip6_frag_queue function in net/ipv6/reassembly.c in the Linux kernel before 2.6.36 allows remote attackers to bypass intended network restrictions via overlapping IPv6 fragments.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-4443

почти 14 лет назад

Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gain privileges by leveraging cgi-bin write access.

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2012-4442

почти 14 лет назад

Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.

CVSS2: 4.7
EPSS: Низкий
nvd логотип

CVE-2012-4441

почти 7 лет назад

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2012-4440

почти 7 лет назад

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2012-4439

почти 7 лет назад

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2012-4438

почти 7 лет назад

Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2012-4437

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger a Smarty exception.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-4436

почти 14 лет назад

Buffer overflow in the run_last_args function in client/fwknop.c in fwknop before 2.0.3, when processing --last, might allow local users to cause a denial of service (client crash) and possibly execute arbitrary code via many .fwknop.run arguments.

CVSS2: 4.4
EPSS: Низкий
nvd логотип

CVE-2012-4435

почти 14 лет назад

fwknop before 2.0.3 does not properly validate IP addresses, which allows remote authenticated users to cause a denial of service (server crash) via a long IP address.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-4434

больше 6 лет назад

fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2012-4433

почти 14 лет назад

Multiple integer overflows in operations/external/ppm-load.c in GEGL (Generic Graphics Library) 0.2.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large (1) width or (2) height value in a Portable Pixel Map (ppm) image, which triggers a heap-based buffer overflow.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2012-4432

почти 14 лет назад

Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-4431

почти 14 лет назад

org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-4430

почти 14 лет назад

The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-4429

почти 14 лет назад

Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-4428

почти 7 лет назад

openslp: SLPIntersectStringList()' Function has a DoS vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2012-4447

Heap-based buffer overflow in tif_pixarlog.c in LibTIFF before 4.0.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF image using the PixarLog Compression format.

CVSS2: 6.8
7%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4446

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.

CVSS2: 6.8
5%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-4445

Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.

CVSS2: 4.3
4%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4444

The ip6_frag_queue function in net/ipv6/reassembly.c in the Linux kernel before 2.6.36 allows remote attackers to bypass intended network restrictions via overlapping IPv6 fragments.

CVSS2: 5
4%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4443

Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gain privileges by leveraging cgi-bin write access.

CVSS2: 6.9
0%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4442

Monkey HTTP Daemon 0.9.3 retains the supplementary group IDs of the root account during operations with a non-root effective UID, which might allow local users to bypass intended file-read restrictions by leveraging a race condition in a file-permission check.

CVSS2: 4.7
0%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4441

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.

CVSS3: 6.1
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-4440

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.

CVSS3: 6.1
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-4439

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

CVSS3: 6.1
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-4438

Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.

CVSS3: 8.8
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2012-4437

Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger a Smarty exception.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4436

Buffer overflow in the run_last_args function in client/fwknop.c in fwknop before 2.0.3, when processing --last, might allow local users to cause a denial of service (client crash) and possibly execute arbitrary code via many .fwknop.run arguments.

CVSS2: 4.4
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4435

fwknop before 2.0.3 does not properly validate IP addresses, which allows remote authenticated users to cause a denial of service (server crash) via a long IP address.

CVSS2: 4
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4434

fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
nvd логотип
CVE-2012-4433

Multiple integer overflows in operations/external/ppm-load.c in GEGL (Generic Graphics Library) 0.2.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large (1) width or (2) height value in a Portable Pixel Map (ppm) image, which triggers a heap-based buffer overflow.

CVSS2: 7.5
13%
Средний
почти 14 лет назад
nvd логотип
CVE-2012-4432

Use-after-free vulnerability in opngreduc.c in OptiPNG Hg and 0.7.x before 0.7.3 might allow remote attackers to execute arbitrary code via unspecified vectors related to "palette reduction."

CVSS2: 7.5
5%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4431

org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.

CVSS2: 4.3
9%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4430

The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.

CVSS2: 4
3%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4429

Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.

CVSS2: 5
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4428

openslp: SLPIntersectStringList()' Function has a DoS vulnerability

CVSS3: 7.5
10%
Низкий
почти 7 лет назад

Уязвимостей на страницу