Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 251

Количество 53 251

redhat логотип

CVE-2012-4447

почти 14 лет назад

Heap-based buffer overflow in tif_pixarlog.c in LibTIFF before 4.0.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF image using the PixarLog Compression format.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2012-4446

больше 13 лет назад

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2012-4445

почти 14 лет назад

Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-4444

больше 16 лет назад

The ip6_frag_queue function in net/ipv6/reassembly.c in the Linux kernel before 2.6.36 allows remote attackers to bypass intended network restrictions via overlapping IPv6 fragments.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2012-4439

почти 14 лет назад

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-4438

почти 14 лет назад

Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.

CVSS2: 6.5
EPSS: Низкий
redhat логотип

CVE-2012-4433

почти 14 лет назад

Multiple integer overflows in operations/external/ppm-load.c in GEGL (Generic Graphics Library) 0.2.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large (1) width or (2) height value in a Portable Pixel Map (ppm) image, which triggers a heap-based buffer overflow.

CVSS2: 6.8
EPSS: Средний
redhat логотип

CVE-2012-4431

больше 13 лет назад

org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-4430

почти 14 лет назад

The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.

CVSS2: 2.7
EPSS: Низкий
redhat логотип

CVE-2012-4429

около 14 лет назад

Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-4428

почти 14 лет назад

openslp: SLPIntersectStringList()' Function has a DoS vulnerability

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-4425

почти 14 лет назад

libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.

CVSS2: 6.9
EPSS: Низкий
redhat логотип

CVE-2012-4424

почти 14 лет назад

Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string that triggers a malloc failure and use of the alloca function.

CVSS2: 3.7
EPSS: Низкий
redhat логотип

CVE-2012-4423

около 14 лет назад

The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with (1) an event as the RPC number or (2) an RPC number whose value is in a "gap" in the RPC dispatch table.

CVSS2: 3.3
EPSS: Низкий
redhat логотип

CVE-2012-4420

почти 14 лет назад

An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements right after the allocation). A remote attacker could use this flaw to obtain potentially sensitive information.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-4418

почти 14 лет назад

Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2012-4417

больше 13 лет назад

GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-4416

почти 14 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Hotspot.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-4414

почти 14 лет назад

Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote authenticated users to execute arbitrary SQL commands via vectors related to the binary log. NOTE: as of 20130116, Oracle has not commented on claims from a downstream vendor that the fix in MySQL 5.5.29 is incomplete.

CVSS2: 2.2
EPSS: Низкий
redhat логотип

CVE-2012-4413

почти 14 лет назад

OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2012-4447

Heap-based buffer overflow in tif_pixarlog.c in LibTIFF before 4.0.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF image using the PixarLog Compression format.

CVSS2: 6.8
7%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-4446

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.

CVSS2: 5.8
5%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-4445

Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.

CVSS2: 5
4%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-4444

The ip6_frag_queue function in net/ipv6/reassembly.c in the Linux kernel before 2.6.36 allows remote attackers to bypass intended network restrictions via overlapping IPv6 fragments.

CVSS2: 2.6
4%
Низкий
больше 16 лет назад
redhat логотип
CVE-2012-4439

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-4438

Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.

CVSS2: 6.5
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-4433

Multiple integer overflows in operations/external/ppm-load.c in GEGL (Generic Graphics Library) 0.2.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large (1) width or (2) height value in a Portable Pixel Map (ppm) image, which triggers a heap-based buffer overflow.

CVSS2: 6.8
13%
Средний
почти 14 лет назад
redhat логотип
CVE-2012-4431

org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.

CVSS2: 4.3
9%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-4430

The dump_resource function in dird/dird_conf.c in Bacula before 5.2.11 does not properly enforce ACL rules, which allows remote authenticated users to obtain resource dump information via unspecified vectors.

CVSS2: 2.7
3%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-4429

Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.

CVSS2: 5
2%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-4428

openslp: SLPIntersectStringList()' Function has a DoS vulnerability

CVSS2: 5
10%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-4425

libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.

CVSS2: 6.9
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-4424

Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string that triggers a malloc failure and use of the alloca function.

CVSS2: 3.7
3%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-4423

The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with (1) an event as the RPC number or (2) an RPC number whose value is in a "gap" in the RPC dispatch table.

CVSS2: 3.3
4%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-4420

An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements right after the allocation). A remote attacker could use this flaw to obtain potentially sensitive information.

CVSS2: 4.3
5%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-4418

Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

CVSS2: 5.8
6%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-4417

GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-4416

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and 6 Update 35 and earlier, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Hotspot.

CVSS2: 4.3
3%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-4414

Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote authenticated users to execute arbitrary SQL commands via vectors related to the binary log. NOTE: as of 20130116, Oracle has not commented on claims from a downstream vendor that the fix in MySQL 5.5.29 is incomplete.

CVSS2: 2.2
3%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-4413

OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.

CVSS2: 4
2%
Низкий
почти 14 лет назад

Уязвимостей на страницу