Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 251

Количество 53 251

redhat логотип

CVE-2012-5597

больше 13 лет назад

[REJECTED CVE] An out of heap-based buffer bounds read flaw was found in the way Wireshark, a network traffic analyzer, performed dissection of certain ISAKMP packets. The issue occurs because dissect_isakmp() function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector uses an incorrect data structure to determine IKEv2 decryption parameters. A remote attacker could provide a specially-crafted ISAKMP packet / packet capture that, when processed, would lead to wireshark executable crash.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5596

больше 13 лет назад

No description is available for this CVE.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5595

больше 13 лет назад

[REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2012-6056. Note: All CVE users should reference CVE-2012-6056 instead of this candidate.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5594

больше 13 лет назад

No description is available for this CVE.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5593

больше 13 лет назад

No description is available for this CVE.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5592

больше 13 лет назад

No description is available for this CVE.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-5582

больше 6 лет назад

opendnssec misuses libcurl API

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2012-5581

почти 14 лет назад

Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DOTRANGE tag in a TIFF image.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2012-5580

больше 13 лет назад

Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as demonstrated using the http_proxy environment variable or a PAC file.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-5576

почти 14 лет назад

Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large (1) red, (2) green, or (3) blue color mask in an XWD file.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2012-5575

больше 13 лет назад

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

CVSS2: 7.8
EPSS: Низкий
redhat логотип

CVE-2012-5571

больше 13 лет назад

A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2012-5562

больше 6 лет назад

A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are exposed to unauthorized parties.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2012-5561

больше 13 лет назад

script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-5536

больше 13 лет назад

A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo.

CVSS2: 6.2
EPSS: Низкий
redhat логотип

CVE-2012-5535

больше 13 лет назад

gnome-system-log polkit policy allows arbitrary files on the system to be read

CVSS2: 4.9
EPSS: Низкий
redhat логотип

CVE-2012-5532

около 14 лет назад

The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2669.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-5531

больше 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal in JBoss Enterprise Portal Platform 5.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5526

больше 13 лет назад

CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2012-5525

больше 13 лет назад

The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service (crash) via a crafted GFN that triggers a buffer over-read.

CVSS2: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2012-5597

[REJECTED CVE] An out of heap-based buffer bounds read flaw was found in the way Wireshark, a network traffic analyzer, performed dissection of certain ISAKMP packets. The issue occurs because dissect_isakmp() function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector uses an incorrect data structure to determine IKEv2 decryption parameters. A remote attacker could provide a specially-crafted ISAKMP packet / packet capture that, when processed, would lead to wireshark executable crash.

CVSS2: 4.3
больше 13 лет назад
redhat логотип
CVE-2012-5596

No description is available for this CVE.

CVSS2: 4.3
больше 13 лет назад
redhat логотип
CVE-2012-5595

[REJECTED CVE] This CVE has been rejected. This candidate is a duplicate of CVE-2012-6056. Note: All CVE users should reference CVE-2012-6056 instead of this candidate.

CVSS2: 4.3
больше 13 лет назад
redhat логотип
CVE-2012-5594

No description is available for this CVE.

CVSS2: 4.3
больше 13 лет назад
redhat логотип
CVE-2012-5593

No description is available for this CVE.

CVSS2: 4.3
больше 13 лет назад
redhat логотип
CVE-2012-5592

No description is available for this CVE.

CVSS2: 2.1
больше 13 лет назад
redhat логотип
CVE-2012-5582

opendnssec misuses libcurl API

CVSS3: 5.1
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2012-5581

Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DOTRANGE tag in a TIFF image.

CVSS2: 6.8
4%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5580

Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as demonstrated using the http_proxy environment variable or a PAC file.

CVSS2: 2.1
3%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5576

Multiple stack-based buffer overflows in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.8.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large (1) red, (2) green, or (3) blue color mask in an XWD file.

CVSS2: 6.8
7%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5575

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowed by the WS-SecurityPolicy AlgorithmSuite definition before decrypting, which allows remote attackers to force CXF to use weaker cryptographic algorithms than intended and makes it easier to decrypt communications, aka "XML Encryption backwards compatibility attack."

CVSS2: 7.8
6%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5571

A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens when a user's role has been removed from a tenant. An attacker can leverage a token associated with a removed user role to gain unauthorized access.

CVSS3: 5.4
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5562

A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are exposed to unauthorized parties.

CVSS3: 8.6
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2012-5561

script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5536

A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo.

CVSS2: 6.2
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5535

gnome-system-log polkit policy allows arbitrary files on the system to be read

CVSS2: 4.9
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5532

The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2669.

CVSS2: 2.1
0%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-5531

Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal in JBoss Enterprise Portal Platform 5.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5526

CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.

CVSS2: 2.6
3%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5525

The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service (crash) via a crafted GFN that triggers a buffer over-read.

CVSS2: 6.5
2%
Низкий
больше 13 лет назад

Уязвимостей на страницу