Количество 53 251
Количество 53 251
CVE-2012-5597
[REJECTED CVE] An out of heap-based buffer bounds read flaw was found in the way Wireshark, a network traffic analyzer, performed dissection of certain ISAKMP packets. The issue occurs because dissect_isakmp() function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector uses an incorrect data structure to determine IKEv2 decryption parameters. A remote attacker could provide a specially-crafted ISAKMP packet / packet capture that, when processed, would lead to wireshark executable crash.
CVE-2012-5596
No description is available for this CVE.
CVE-2012-5595
[REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2012-6056. Note: All CVE users should reference CVE-2012-6056 instead of this candidate.
CVE-2012-5594
No description is available for this CVE.
CVE-2012-5593
No description is available for this CVE.
CVE-2012-5592
No description is available for this CVE.
CVE-2012-5582
opendnssec misuses libcurl API
CVE-2012-5581
Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DOTRANGE tag in a TIFF image.
CVE-2012-5580
Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as demonstrated using the http_proxy environment variable or a PAC file.
CVE-2012-5576
Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large (1) red, (2) green, or (3) blue color mask in an XWD file.
CVE-2012-5575
Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."
CVE-2012-5571
A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.
CVE-2012-5562
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are exposed to unauthorized parties.
CVE-2012-5561
script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.
CVE-2012-5536
A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo.
CVE-2012-5535
gnome-system-log polkit policy allows arbitrary files on the system to be read
CVE-2012-5532
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2669.
CVE-2012-5531
Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal in JBoss Enterprise Portal Platform 5.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2012-5526
CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.
CVE-2012-5525
The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service (crash) via a crafted GFN that triggers a buffer over-read.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2012-5597 [REJECTED CVE] An out of heap-based buffer bounds read flaw was found in the way Wireshark, a network traffic analyzer, performed dissection of certain ISAKMP packets. The issue occurs because dissect_isakmp() function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector uses an incorrect data structure to determine IKEv2 decryption parameters. A remote attacker could provide a specially-crafted ISAKMP packet / packet capture that, when processed, would lead to wireshark executable crash. | CVSS2: 4.3 | больше 13 лет назад | ||
CVE-2012-5596 No description is available for this CVE. | CVSS2: 4.3 | больше 13 лет назад | ||
CVE-2012-5595 [REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2012-6056. Note: All CVE users should reference CVE-2012-6056 instead of this candidate. | CVSS2: 4.3 | больше 13 лет назад | ||
CVE-2012-5594 No description is available for this CVE. | CVSS2: 4.3 | больше 13 лет назад | ||
CVE-2012-5593 No description is available for this CVE. | CVSS2: 4.3 | больше 13 лет назад | ||
CVE-2012-5592 No description is available for this CVE. | CVSS2: 2.1 | больше 13 лет назад | ||
CVE-2012-5582 opendnssec misuses libcurl API | CVSS3: 5.1 | 2% Низкий | больше 6 лет назад | |
CVE-2012-5581 Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DOTRANGE tag in a TIFF image. | CVSS2: 6.8 | 4% Низкий | почти 14 лет назад | |
CVE-2012-5580 Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as demonstrated using the http_proxy environment variable or a PAC file. | CVSS2: 2.1 | 3% Низкий | больше 13 лет назад | |
CVE-2012-5576 Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large (1) red, (2) green, or (3) blue color mask in an XWD file. | CVSS2: 6.8 | 7% Низкий | почти 14 лет назад | |
CVE-2012-5575 Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack." | CVSS2: 7.8 | 6% Низкий | больше 13 лет назад | |
CVE-2012-5571 A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access. | CVSS3: 5.4 | 2% Низкий | больше 13 лет назад | |
CVE-2012-5562 A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are exposed to unauthorized parties. | CVSS3: 8.6 | 1% Низкий | больше 6 лет назад | |
CVE-2012-5561 script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file. | CVSS2: 2.1 | 0% Низкий | больше 13 лет назад | |
CVE-2012-5536 A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo. | CVSS2: 6.2 | 0% Низкий | больше 13 лет назад | |
CVE-2012-5535 gnome-system-log polkit policy allows arbitrary files on the system to be read | CVSS2: 4.9 | 2% Низкий | больше 13 лет назад | |
CVE-2012-5532 The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2669. | CVSS2: 2.1 | 0% Низкий | около 14 лет назад | |
CVE-2012-5531 Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal in JBoss Enterprise Portal Platform 5.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | CVSS2: 4.3 | 1% Низкий | больше 13 лет назад | |
CVE-2012-5526 CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm. | CVSS2: 2.6 | 3% Низкий | больше 13 лет назад | |
CVE-2012-5525 The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service (crash) via a crafted GFN that triggers a buffer over-read. | CVSS2: 6.5 | 2% Низкий | больше 13 лет назад |
Уязвимостей на страницу