Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 251

Количество 53 251

redhat логотип

CVE-2012-5667

больше 13 лет назад

Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via vectors involving a long input line that triggers a heap-based buffer overflow.

CVSS2: 4.4
EPSS: Низкий
redhat логотип

CVE-2012-5664

больше 13 лет назад

No description is available for this CVE.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2012-5662

больше 13 лет назад

x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2012-5660

больше 13 лет назад

abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."

CVSS2: 6.6
EPSS: Низкий
redhat логотип

CVE-2012-5659

больше 13 лет назад

Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module.

CVSS2: 3.7
EPSS: Низкий
redhat логотип

CVE-2012-5658

больше 13 лет назад

rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including log files or Bugzilla reports in support channels.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-5656

больше 13 лет назад

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5647

больше 13 лет назад

Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the PATH_INFO.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5646

больше 13 лет назад

node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uuid in the PATH_INFO.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2012-5644

больше 13 лет назад

libuser has information disclosure when moving user's home directory

CVSS2: 4.7
EPSS: Низкий
redhat логотип

CVE-2012-5643

больше 13 лет назад

Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2012-5639

больше 13 лет назад

LibreOffice and OpenOffice automatically open embedded content

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5638

почти 14 лет назад

The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-5635

больше 13 лет назад

The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-5634

больше 13 лет назад

Xen 4.2.x, 4.1.x, and 4.0, when using Intel VT-d for PCI passthrough, does not properly configure VT-d when supporting a device that is behind a legacy PCI Bridge, which allows local guests to cause a denial of service to other guests by injecting an interrupt.

CVSS2: 5.2
EPSS: Низкий
redhat логотип

CVE-2012-5633

больше 13 лет назад

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2012-5631

почти 14 лет назад

ipa 3.0 does not properly check server identity before sending credential containing cookies

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5630

больше 13 лет назад

libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.

CVSS2: 3.7
EPSS: Низкий
redhat логотип

CVE-2012-5629

больше 13 лет назад

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2012-5628

больше 14 лет назад

gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries.

CVSS2: 1.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2012-5667

Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via vectors involving a long input line that triggers a heap-based buffer overflow.

CVSS2: 4.4
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5664

No description is available for this CVE.

CVSS2: 6.4
больше 13 лет назад
redhat логотип
CVE-2012-5662

x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 5.8
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5660

abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."

CVSS2: 6.6
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5659

Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module.

CVSS2: 3.7
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5658

rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including log files or Bugzilla reports in support channels.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5656

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

CVSS2: 5
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5647

Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the PATH_INFO.

CVSS2: 5
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5646

node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uuid in the PATH_INFO.

CVSS2: 7.5
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5644

libuser has information disclosure when moving user's home directory

CVSS2: 4.7
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5643

Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.

CVSS2: 5
23%
Средний
больше 13 лет назад
redhat логотип
CVE-2012-5639

LibreOffice and OpenOffice automatically open embedded content

CVSS2: 4.3
6%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5638

The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.

CVSS2: 2.1
0%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5635

The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5634

Xen 4.2.x, 4.1.x, and 4.0, when using Intel VT-d for PCI passthrough, does not properly configure VT-d when supporting a device that is behind a legacy PCI Bridge, which allows local guests to cause a denial of service to other guests by injecting an interrupt.

CVSS2: 5.2
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5633

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

CVSS2: 6.4
8%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5631

ipa 3.0 does not properly check server identity before sending credential containing cookies

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5630

libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.

CVSS2: 3.7
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5629

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

CVSS2: 7.5
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5628

gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries.

CVSS2: 1.9
0%
Низкий
больше 14 лет назад

Уязвимостей на страницу