Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 57 013

Количество 57 013

redhat логотип

CVE-2012-5658

больше 13 лет назад

rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including log files or Bugzilla reports in support channels.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-5656

больше 13 лет назад

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5647

больше 13 лет назад

Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the PATH_INFO.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5646

больше 13 лет назад

node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uuid in the PATH_INFO.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2012-5644

больше 13 лет назад

libuser has information disclosure when moving user's home directory

CVSS2: 4.7
EPSS: Низкий
redhat логотип

CVE-2012-5643

больше 13 лет назад

Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2012-5639

почти 14 лет назад

LibreOffice and OpenOffice automatically open embedded content

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5638

около 14 лет назад

The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-5635

больше 13 лет назад

The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2012-5634

больше 13 лет назад

Xen 4.2.x, 4.1.x, and 4.0, when using Intel VT-d for PCI passthrough, does not properly configure VT-d when supporting a device that is behind a legacy PCI Bridge, which allows local guests to cause a denial of service to other guests by injecting an interrupt.

CVSS2: 5.2
EPSS: Низкий
redhat логотип

CVE-2012-5633

больше 13 лет назад

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

CVSS2: 6.4
EPSS: Низкий
redhat логотип

CVE-2012-5631

почти 14 лет назад

ipa 3.0 does not properly check server identity before sending credential containing cookies

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5630

больше 13 лет назад

libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.

CVSS2: 3.7
EPSS: Низкий
redhat логотип

CVE-2012-5629

больше 13 лет назад

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2012-5628

больше 14 лет назад

gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries.

CVSS2: 1.9
EPSS: Низкий
redhat логотип

CVE-2012-5627

почти 14 лет назад

Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

CVSS2: 2.6
EPSS: Средний
redhat логотип

CVE-2012-5626

больше 11 лет назад

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2012-5625

больше 13 лет назад

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2012-5624

почти 14 лет назад

The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5622

почти 14 лет назад

Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application_controller.rb) in OpenShift 0.0.5 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors.

CVSS2: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2012-5658

rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including log files or Bugzilla reports in support channels.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5656

The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.

CVSS2: 5
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5647

Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the PATH_INFO.

CVSS2: 5
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5646

node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uuid in the PATH_INFO.

CVSS2: 7.5
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5644

libuser has information disclosure when moving user's home directory

CVSS2: 4.7
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5643

Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.

CVSS2: 5
23%
Средний
больше 13 лет назад
redhat логотип
CVE-2012-5639

LibreOffice and OpenOffice automatically open embedded content

CVSS2: 4.3
6%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5638

The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.

CVSS2: 2.1
0%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-5635

The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5634

Xen 4.2.x, 4.1.x, and 4.0, when using Intel VT-d for PCI passthrough, does not properly configure VT-d when supporting a device that is behind a legacy PCI Bridge, which allows local guests to cause a denial of service to other guests by injecting an interrupt.

CVSS2: 5.2
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5633

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

CVSS2: 6.4
8%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5631

ipa 3.0 does not properly check server identity before sending credential containing cookies

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5630

libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.

CVSS2: 3.7
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5629

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

CVSS2: 7.5
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5628

gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries.

CVSS2: 1.9
0%
Низкий
больше 14 лет назад
redhat логотип
CVE-2012-5627

Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

CVSS2: 2.6
11%
Средний
почти 14 лет назад
redhat логотип
CVE-2012-5626

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.

CVSS2: 2.6
1%
Низкий
больше 11 лет назад
redhat логотип
CVE-2012-5625

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).

CVSS3: 6.5
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5624

The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5622

Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application_controller.rb) in OpenShift 0.0.5 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors.

CVSS2: 5.1
1%
Низкий
почти 14 лет назад

Уязвимостей на страницу