Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 251

Количество 53 251

redhat логотип

CVE-2012-5521

больше 13 лет назад

quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal

CVSS2: 2.9
EPSS: Низкий
redhat логотип

CVE-2012-5519

почти 14 лет назад

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

CVSS2: 7.4
EPSS: Низкий
redhat логотип

CVE-2012-5518

почти 14 лет назад

vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2012-5517

около 14 лет назад

The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact in opportunistic circumstances by using memory that was hot-added by an administrator.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2012-5516

больше 13 лет назад

Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when moving disks between storage domains, does not properly wipe-after-delete, which prevents disks from being securely deleted and might allow local users to obtain sensitive information via unspecified vectors.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-5515

больше 13 лет назад

The (1) XENMEM_decrease_reservation, (2) XENMEM_populate_physmap, and (3) XENMEM_exchange hypercalls in Xen 4.2 and earlier allow local guest administrators to cause a denial of service (long loop and hang) via a crafted extent_order value.

CVSS2: 5.5
EPSS: Низкий
redhat логотип

CVE-2012-5514

больше 13 лет назад

The guest_physmap_mark_populate_on_demand function in Xen 4.2 and earlier does not properly unlock the subject GFNs when checking if they are in use, which allows local guest HVM administrators to cause a denial of service (hang) via unspecified vectors.

CVSS2: 5.5
EPSS: Низкий
redhat логотип

CVE-2012-5513

больше 13 лет назад

The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause a denial of service (crash) or possibly gain privileges via unspecified vectors that overwrite memory in the hypervisor reserved range.

CVSS2: 7.4
EPSS: Низкий
redhat логотип

CVE-2012-5512

больше 13 лет назад

Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.

CVSS2: 5.9
EPSS: Низкий
redhat логотип

CVE-2012-5511

больше 13 лет назад

Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3.4 through 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) via a large bitmap image.

CVSS2: 5.5
EPSS: Низкий
redhat логотип

CVE-2012-5510

больше 13 лет назад

Xen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors.

CVSS2: 5.5
EPSS: Низкий
redhat логотип

CVE-2012-5509

больше 13 лет назад

aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-5508

почти 14 лет назад

The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password resets via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6661 was assigned for the PRNG reseeding issue in Zope.

CVSS2: 1.8
EPSS: Низкий
redhat логотип

CVE-2012-5507

почти 14 лет назад

AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.

CVSS2: 1.8
EPSS: Низкий
redhat логотип

CVE-2012-5506

почти 14 лет назад

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (infinite loop) via an RSS feed request for a folder the user does not have permission to access.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5505

почти 14 лет назад

atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a request for a view without a name.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5504

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in widget_traversal.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5503

почти 14 лет назад

ftp.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read hidden folder contents via unspecified vectors.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5502

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in safe_html.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with permissions to edit content to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 3.5
EPSS: Низкий
redhat логотип

CVE-2012-5501

почти 14 лет назад

at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom content types via a crafted URL.

CVSS2: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2012-5521

quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal

CVSS2: 2.9
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5519

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

CVSS2: 7.4
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5518

vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)

CVSS2: 6.8
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5517

The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact in opportunistic circumstances by using memory that was hot-added by an administrator.

CVSS2: 4
0%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-5516

Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when moving disks between storage domains, does not properly wipe-after-delete, which prevents disks from being securely deleted and might allow local users to obtain sensitive information via unspecified vectors.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5515

The (1) XENMEM_decrease_reservation, (2) XENMEM_populate_physmap, and (3) XENMEM_exchange hypercalls in Xen 4.2 and earlier allow local guest administrators to cause a denial of service (long loop and hang) via a crafted extent_order value.

CVSS2: 5.5
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5514

The guest_physmap_mark_populate_on_demand function in Xen 4.2 and earlier does not properly unlock the subject GFNs when checking if they are in use, which allows local guest HVM administrators to cause a denial of service (hang) via unspecified vectors.

CVSS2: 5.5
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5513

The XENMEM_exchange handler in Xen 4.2 and earlier does not properly check the memory address, which allows local PV guest OS administrators to cause a denial of service (crash) or possibly gain privileges via unspecified vectors that overwrite memory in the hypervisor reserved range.

CVSS2: 7.4
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5512

Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors.

CVSS2: 5.9
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5511

Stack-based buffer overflow in the dirty video RAM tracking functionality in Xen 3.4 through 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) via a large bitmap image.

CVSS2: 5.5
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5510

Xen 4.x, when downgrading the grant table version, does not properly remove the status page from the tracking list when freeing the page, which allows local guest OS administrators to cause a denial of service (hypervisor crash) via unspecified vectors.

CVSS2: 5.5
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5509

aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5508

The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password resets via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6661 was assigned for the PRNG reseeding issue in Zope.

CVSS2: 1.8
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5507

AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.

CVSS2: 1.8
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5506

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (infinite loop) via an RSS feed request for a folder the user does not have permission to access.

CVSS2: 5
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5505

atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a request for a view without a name.

CVSS2: 5
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5504

Cross-site scripting (XSS) vulnerability in widget_traversal.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 5
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5503

ftp.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read hidden folder contents via unspecified vectors.

CVSS2: 5
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5502

Cross-site scripting (XSS) vulnerability in safe_html.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with permissions to edit content to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 3.5
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5501

at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom content types via a crafted URL.

CVSS2: 6.4
1%
Низкий
почти 14 лет назад

Уязвимостей на страницу