Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 57 017

Количество 57 017

redhat логотип

CVE-2012-5626

больше 11 лет назад

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2012-5625

больше 13 лет назад

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2012-5624

почти 14 лет назад

The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5622

почти 14 лет назад

Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application_controller.rb) in OpenShift 0.0.5 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2012-5621

около 15 лет назад

lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection with a party name that contains invalid UTF-8 strings.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5620

почти 14 лет назад

No description is available for this CVE.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2012-5615

почти 14 лет назад

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

CVSS2: 3.5
EPSS: Средний
redhat логотип

CVE-2012-5614

почти 14 лет назад

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

CVSS2: 4
EPSS: Средний
redhat логотип

CVE-2012-5613

почти 14 лет назад

MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.

CVSS2: 4.6
EPSS: Средний
redhat логотип

CVE-2012-5612

почти 14 лет назад

Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands.

CVSS2: 6.5
EPSS: Средний
redhat логотип

CVE-2012-5611

почти 14 лет назад

Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.

CVSS2: 6.5
EPSS: Средний
redhat логотип

CVE-2012-5605

больше 13 лет назад

Grinder in Red Hat CloudForms before 1.1 uses world-writable permissions for /var/lib/pulp/cache/grinder/, which allows local users to modify grinder cache files.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2012-5604

почти 14 лет назад

The ldap_fluff gem for Ruby, as used in Red Hat CloudForms 1.1, when using Active Directory for authentication, allows remote attackers to bypass authentication via unspecified vectors.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5603

почти 14 лет назад

proxies_controller.rb in Katello in Red Hat CloudForms before 1.1 does not properly check permissions, which allows remote authenticated users to read consumer certificates or change arbitrary users' settings via unspecified vectors related to the "consumer UUID" of a system.

CVSS2: 5.5
EPSS: Низкий
redhat логотип

CVE-2012-5602

почти 14 лет назад

No description is available for this CVE.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5601

почти 14 лет назад

No description is available for this CVE.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5600

почти 14 лет назад

[REJECTED CVE] A denial of service flaw was found in the way RTCP dissector of Wireshark, a network traffic analyzer, performed dissection of certain RTCP packet capture files. A remote attacker could provide a specially-crafted RTCP packet / packet capture that, once processed, would lead to excessive CPU consumption or into situation where tshark executable would enter an infinite loop, when trying to process the crafted packet / packet capture file.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5599

почти 14 лет назад

[REJECTED CVE] A denial of service flaw was found in the way WTP dissector of Wireshark, a network traffic analyzer, performed dissection of certain WTP packet capture files. A remote attacker could provide a specially-crafted WTP packet / packet capture that, once processed, would lead to excessive CPU consumption or into situation where tshark executable would enter an infinite loop, when trying to process the crafted packet / packet capture file.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5598

почти 14 лет назад

[REJECTED CVE] An integer overflow vulnerability has been identified in the dissect_iscsi_pdu() function in epan/dissectors/packet-iscsi.c in the iSCSI dissector in Wireshark. A remote attacker could provide a specially-crafted iSCSI packet / packet capture that, once processed, would lead to excessive CPU consumption or into situation where tshark executable would enter an infinite loop, when trying to process the crafted packet / packet capture file.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5597

почти 14 лет назад

[REJECTED CVE] An out of heap-based buffer bounds read flaw was found in the way Wireshark, a network traffic analyzer, performed dissection of certain ISAKMP packets. The issue occurs because dissect_isakmp() function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector uses an incorrect data structure to determine IKEv2 decryption parameters. A remote attacker could provide a specially-crafted ISAKMP packet / packet capture that, when processed, would lead to wireshark executable crash.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2012-5626

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.

CVSS2: 2.6
1%
Низкий
больше 11 лет назад
redhat логотип
CVE-2012-5625

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).

CVSS3: 6.5
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5624

The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5622

Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application_controller.rb) in OpenShift 0.0.5 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors.

CVSS2: 5.1
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5621

lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection with a party name that contains invalid UTF-8 strings.

CVSS2: 5
3%
Низкий
около 15 лет назад
redhat логотип
CVE-2012-5620

No description is available for this CVE.

CVSS2: 4
почти 14 лет назад
redhat логотип
CVE-2012-5615

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

CVSS2: 3.5
15%
Средний
почти 14 лет назад
redhat логотип
CVE-2012-5614

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

CVSS2: 4
13%
Средний
почти 14 лет назад
redhat логотип
CVE-2012-5613

MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.

CVSS2: 4.6
32%
Средний
почти 14 лет назад
redhat логотип
CVE-2012-5612

Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code, as demonstrated using certain variations of the (1) USE, (2) SHOW TABLES, (3) DESCRIBE, (4) SHOW FIELDS FROM, (5) SHOW COLUMNS FROM, (6) SHOW INDEX FROM, (7) CREATE TABLE, (8) DROP TABLE, (9) ALTER TABLE, (10) DELETE FROM, (11) UPDATE, and (12) SET PASSWORD commands.

CVSS2: 6.5
21%
Средний
почти 14 лет назад
redhat логотип
CVE-2012-5611

Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.

CVSS2: 6.5
24%
Средний
почти 14 лет назад
redhat логотип
CVE-2012-5605

Grinder in Red Hat CloudForms before 1.1 uses world-writable permissions for /var/lib/pulp/cache/grinder/, which allows local users to modify grinder cache files.

CVSS3: 3.3
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5604

The ldap_fluff gem for Ruby, as used in Red Hat CloudForms 1.1, when using Active Directory for authentication, allows remote attackers to bypass authentication via unspecified vectors.

CVSS2: 5
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5603

proxies_controller.rb in Katello in Red Hat CloudForms before 1.1 does not properly check permissions, which allows remote authenticated users to read consumer certificates or change arbitrary users' settings via unspecified vectors related to the "consumer UUID" of a system.

CVSS2: 5.5
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5602

No description is available for this CVE.

CVSS2: 4.3
почти 14 лет назад
redhat логотип
CVE-2012-5601

No description is available for this CVE.

CVSS2: 4.3
почти 14 лет назад
redhat логотип
CVE-2012-5600

[REJECTED CVE] A denial of service flaw was found in the way RTCP dissector of Wireshark, a network traffic analyzer, performed dissection of certain RTCP packet capture files. A remote attacker could provide a specially-crafted RTCP packet / packet capture that, once processed, would lead to excessive CPU consumption or into situation where tshark executable would enter an infinite loop, when trying to process the crafted packet / packet capture file.

CVSS2: 4.3
почти 14 лет назад
redhat логотип
CVE-2012-5599

[REJECTED CVE] A denial of service flaw was found in the way WTP dissector of Wireshark, a network traffic analyzer, performed dissection of certain WTP packet capture files. A remote attacker could provide a specially-crafted WTP packet / packet capture that, once processed, would lead to excessive CPU consumption or into situation where tshark executable would enter an infinite loop, when trying to process the crafted packet / packet capture file.

CVSS2: 4.3
почти 14 лет назад
redhat логотип
CVE-2012-5598

[REJECTED CVE] An integer overflow vulnerability has been identified in the dissect_iscsi_pdu() function in epan/dissectors/packet-iscsi.c in the iSCSI dissector in Wireshark. A remote attacker could provide a specially-crafted iSCSI packet / packet capture that, once processed, would lead to excessive CPU consumption or into situation where tshark executable would enter an infinite loop, when trying to process the crafted packet / packet capture file.

CVSS2: 4.3
почти 14 лет назад
redhat логотип
CVE-2012-5597

[REJECTED CVE] An out of heap-based buffer bounds read flaw was found in the way Wireshark, a network traffic analyzer, performed dissection of certain ISAKMP packets. The issue occurs because dissect_isakmp() function in epan/dissectors/packet-isakmp.c in the ISAKMP dissector uses an incorrect data structure to determine IKEv2 decryption parameters. A remote attacker could provide a specially-crafted ISAKMP packet / packet capture that, when processed, would lead to wireshark executable crash.

CVSS2: 4.3
почти 14 лет назад

Уязвимостей на страницу