Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 269

Количество 53 269

redhat логотип

CVE-2012-6149

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) content values of a note in a system.addNote XML-RPC call.

CVSS2: 3.5
EPSS: Низкий
redhat логотип

CVE-2012-6139

почти 14 лет назад

libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized variable to the xsltDocumentFunction function in functions.c.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-6137

больше 13 лет назад

rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-6136

около 14 лет назад

tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2012-6135

больше 13 лет назад

RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-6120

почти 14 лет назад

Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-6119

около 14 лет назад

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2012-6118

больше 13 лет назад

The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instances quota user setting.

CVSS2: 5.5
EPSS: Низкий
redhat логотип

CVE-2012-6117

почти 14 лет назад

Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-6116

больше 13 лет назад

modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.

CVSS2: 4.6
EPSS: Низкий
redhat логотип

CVE-2012-6115

больше 13 лет назад

The domain management tool (rhevm-manage-domains) in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier, when the validate action is enabled, logs the administrative password to a world-readable log file, which allows local users to obtain sensitive information by reading this file.

CVSS2: 4.7
EPSS: Низкий
redhat логотип

CVE-2012-6113

больше 14 лет назад

The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process memory by providing zero bytes of input data.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-6109

больше 14 лет назад

lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a crafted Content-Disposion header.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-6108

больше 13 лет назад

HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp, which allows local users to delete log files via standard filesystem operations.

CVSS2: 1.9
EPSS: Низкий
redhat логотип

CVE-2012-6097

почти 14 лет назад

File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-6094

больше 13 лет назад

cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2012-6093

больше 13 лет назад

The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-6092

почти 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-6090

больше 13 лет назад

Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-6089

больше 13 лет назад

Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2012-6149

Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) content values of a note in a system.addNote XML-RPC call.

CVSS2: 3.5
2%
Низкий
больше 12 лет назад
redhat логотип
CVE-2012-6139

libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized variable to the xsltDocumentFunction function in functions.c.

CVSS2: 4.3
4%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-6137

rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-6136

tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

CVSS2: 4
0%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-6135

RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

CVSS2: 2.1
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-6120

Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.

CVSS2: 2.1
0%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-6119

Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.

CVSS2: 4
0%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-6118

The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instances quota user setting.

CVSS2: 5.5
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-6117

Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.

CVSS2: 2.1
0%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-6116

modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.

CVSS2: 4.6
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-6115

The domain management tool (rhevm-manage-domains) in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier, when the validate action is enabled, logs the administrative password to a world-readable log file, which allows local users to obtain sensitive information by reading this file.

CVSS2: 4.7
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-6113

The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive information from process memory by providing zero bytes of input data.

CVSS2: 2.1
3%
Низкий
больше 14 лет назад
redhat логотип
CVE-2012-6109

lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a crafted Content-Disposion header.

CVSS2: 4.3
3%
Низкий
больше 14 лет назад
redhat логотип
CVE-2012-6108

HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp, which allows local users to delete log files via standard filesystem operations.

CVSS2: 1.9
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-6097

File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.

CVSS2: 2.1
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-6094

cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

CVSS2: 6.8
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-6093

The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.

CVSS2: 4.3
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-6092

Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.

CVSS2: 4.3
7%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-6090

Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

CVSS2: 2.1
3%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-6089

Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

CVSS2: 2.1
4%
Низкий
больше 13 лет назад

Уязвимостей на страницу