Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 71 741

Количество 71 741

ubuntu логотип

CVE-2012-4537

почти 14 лет назад

Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability."

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2012-4536

почти 14 лет назад

The (1) domain_pirq_to_emuirq and (2) physdev_unmap_pirq functions in Xen 2.2 allows local guest OS administrators to cause a denial of service (Xen crash) via a crafted pirq value that triggers an out-of-bounds read.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2012-4535

почти 14 лет назад

Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline."

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2012-4534

больше 13 лет назад

org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2012-4533

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository commit access to inject arbitrary web script or HTML via the "function name" line.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-4530

больше 13 лет назад

The load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2012-4529

почти 13 лет назад

The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-4528

больше 13 лет назад

The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2012-4527

почти 14 лет назад

Stack-based buffer overflow in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name. NOTE: it is not clear whether this is a vulnerability.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-4526

почти 7 лет назад

piwigo has XSS in password.php (incomplete fix for CVE-2012-4525)

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2012-4525

почти 7 лет назад

piwigo has XSS in password.php

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2012-4524

почти 7 лет назад

xlockmore before 5.43 'dclock' security bypass vulnerability

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-4523

почти 14 лет назад

radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2012-4522

почти 14 лет назад

The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-4520

почти 14 лет назад

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2012-4516

почти 14 лет назад

librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the address resolution information for the application via a malicious ib_acm service.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2012-4515

почти 14 лет назад

Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being updated.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-4514

почти 14 лет назад

rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-4513

почти 14 лет назад

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.

CVSS2: 6.4
EPSS: Средний
ubuntu логотип

CVE-2012-4512

больше 6 лет назад

The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-4537

Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability."

CVSS2: 2.1
0%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4536

The (1) domain_pirq_to_emuirq and (2) physdev_unmap_pirq functions in Xen 2.2 allows local guest OS administrators to cause a denial of service (Xen crash) via a crafted pirq value that triggers an out-of-bounds read.

CVSS2: 2.1
0%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4535

Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline."

CVSS2: 1.9
0%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4534

org/apache/tomcat/util/net/NioEndpoint.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28, when the NIO connector is used in conjunction with sendfile and HTTPS, allows remote attackers to cause a denial of service (infinite loop) by terminating the connection during the reading of a response.

CVSS2: 2.6
7%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4533

Cross-site scripting (XSS) vulnerability in the "extra" details in the DiffSource._get_row function in lib/viewvc.py in ViewVC 1.0.x before 1.0.13 and 1.1.x before 1.1.16 allows remote authenticated users with repository commit access to inject arbitrary web script or HTML via the "function name" line.

CVSS2: 4.3
3%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4530

The load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.

CVSS2: 2.1
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4529

The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-4528

The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.

CVSS2: 5
13%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2012-4527

Stack-based buffer overflow in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name. NOTE: it is not clear whether this is a vulnerability.

CVSS2: 6.8
8%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4526

piwigo has XSS in password.php (incomplete fix for CVE-2012-4525)

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-4525

piwigo has XSS in password.php

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-4524

xlockmore before 5.43 'dclock' security bypass vulnerability

CVSS3: 7.5
3%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-4523

radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients.

CVSS2: 6.4
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4522

The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to create files in unexpected locations or with unexpected names via a NUL byte in a file path.

CVSS2: 5
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4520

The django.http.HttpRequest.get_host function in Django 1.3.x before 1.3.4 and 1.4.x before 1.4.2 allows remote attackers to generate and display arbitrary URLs via crafted username and password Host header values.

CVSS2: 6.4
4%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4516

librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the address resolution information for the application via a malicious ib_acm service.

CVSS2: 5.8
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4515

Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being updated.

CVSS2: 6.8
6%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4514

rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."

CVSS2: 5
10%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4513

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.

CVSS2: 6.4
13%
Средний
почти 14 лет назад
ubuntu логотип
CVE-2012-4512

The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."

CVSS3: 8.8
12%
Средний
больше 6 лет назад

Уязвимостей на страницу