Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 269

Количество 53 269

redhat логотип

CVE-2012-6689

больше 11 лет назад

The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.

CVSS2: 4.4
EPSS: Низкий
redhat логотип

CVE-2012-6687

около 14 лет назад

FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-6686

больше 15 лет назад

[REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2013-4357. Note: All CVE users should reference CVE-2013-4357 instead of this candidate.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-6685

около 14 лет назад

Nokogiri before 1.5.4 is vulnerable to XXE attacks

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-6684

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-6662

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-6661

почти 14 лет назад

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).

CVSS2: 1.8
EPSS: Низкий
redhat логотип

CVE-2012-6657

почти 14 лет назад

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.

CVSS2: 4.4
EPSS: Низкий
redhat логотип

CVE-2012-6656

около 14 лет назад

iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when converting IBM930 encoded data to UTF-8.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-6655

почти 14 лет назад

An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.

CVSS2: 1.9
EPSS: Низкий
redhat логотип

CVE-2012-6647

около 14 лет назад

The futex_wait_requeue_pi function in kernel/futex.c in the Linux kernel before 3.5.1 does not ensure that calls have two different futex addresses, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted FUTEX_WAIT_REQUEUE_PI command.

CVSS2: 4.9
EPSS: Низкий
redhat логотип

CVE-2012-6639

больше 12 лет назад

An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.

CVSS2: 7.1
EPSS: Низкий
redhat логотип

CVE-2012-6638

больше 14 лет назад

The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (kernel resource consumption) via a flood of SYN+FIN TCP packets, a different vulnerability than CVE-2012-2663.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2012-6619

больше 13 лет назад

The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (crash) or read system memory via a crafted BSON object in the column name in an insert command, which triggers a buffer over-read.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2012-6617

больше 13 лет назад

The prepare_sdp_description function in ffserver.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (crash) via vectors related to the rtp format.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-6612

почти 14 лет назад

The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2012-6607

больше 12 лет назад

The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsave file in a backup save action, a different vector than CVE-2012-0786.

CVSS2: 3.3
EPSS: Низкий
redhat логотип

CVE-2012-6551

почти 14 лет назад

The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-6549

почти 14 лет назад

The isofs_export_encode_fh function in fs/isofs/export.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.

CVSS2: 1.9
EPSS: Низкий
redhat логотип

CVE-2012-6548

почти 14 лет назад

The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.

CVSS2: 1.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2012-6689

The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.

CVSS2: 4.4
0%
Низкий
больше 11 лет назад
redhat логотип
CVE-2012-6687

FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.

CVSS2: 5
6%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-6686

[REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2013-4357. Note: All CVE users should reference CVE-2013-4357 instead of this candidate.

CVSS2: 4.3
больше 15 лет назад
redhat логотип
CVE-2012-6685

Nokogiri before 1.5.4 is vulnerable to XXE attacks

CVSS2: 5
2%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-6684

Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI.

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
redhat логотип
CVE-2012-6662

Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.

CVSS2: 4.3
6%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-6661

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).

CVSS2: 1.8
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-6657

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.

CVSS2: 4.4
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-6656

iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when converting IBM930 encoded data to UTF-8.

CVSS2: 2.1
3%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-6655

An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.

CVSS2: 1.9
0%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-6647

The futex_wait_requeue_pi function in kernel/futex.c in the Linux kernel before 3.5.1 does not ensure that calls have two different futex addresses, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted FUTEX_WAIT_REQUEUE_PI command.

CVSS2: 4.9
0%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-6639

An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.

CVSS2: 7.1
2%
Низкий
больше 12 лет назад
redhat логотип
CVE-2012-6638

The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (kernel resource consumption) via a flood of SYN+FIN TCP packets, a different vulnerability than CVE-2012-2663.

CVSS2: 6.4
3%
Низкий
больше 14 лет назад
redhat логотип
CVE-2012-6619

The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (crash) or read system memory via a crafted BSON object in the column name in an insert command, which triggers a buffer over-read.

CVSS2: 5.8
4%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-6617

The prepare_sdp_description function in ffserver.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (crash) via vectors related to the rtp format.

CVSS2: 4.3
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-6612

The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, different vectors than CVE-2013-6407.

CVSS2: 5
10%
Средний
почти 14 лет назад
redhat логотип
CVE-2012-6607

The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsave file in a backup save action, a different vector than CVE-2012-0786.

CVSS2: 3.3
0%
Низкий
больше 12 лет назад
redhat логотип
CVE-2012-6551

The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.

CVSS2: 5
8%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-6549

The isofs_export_encode_fh function in fs/isofs/export.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.

CVSS2: 1.9
0%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-6548

The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.

CVSS2: 1.9
0%
Низкий
почти 14 лет назад

Уязвимостей на страницу