Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 202

Количество 77 202

ubuntu логотип

CVE-2012-6090

больше 13 лет назад

Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-6089

больше 13 лет назад

Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-6088

больше 13 лет назад

The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-6087

почти 13 лет назад

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2012-6086

больше 12 лет назад

libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc1, and 2.1.x before 2.1.2 does not properly set the CURLOPT_SSL_VERIFYHOST option for libcurl, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-6085

больше 13 лет назад

The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corrupt the public keyring database or cause a denial of service (application crash) via a crafted length field of an OpenPGP packet.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2012-6084

больше 13 лет назад

modules/m_capab.c in (1) ircd-ratbox before 3.0.8 and (2) Charybdis before 3.4.2 does not properly support capability negotiation during server handshakes, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed request.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-6083

больше 6 лет назад

Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2012-6082

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-6081

больше 13 лет назад

Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as exploited in the wild in July 2012.

CVSS2: 6
EPSS: Средний
ubuntu логотип

CVE-2012-6080

больше 13 лет назад

Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a file name.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2012-6076

больше 13 лет назад

Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive information, and possibly have other unspecified impacts.

CVSS2: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2012-6075

больше 13 лет назад

Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2012-6074

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote authenticated users with write access to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-6073

больше 13 лет назад

Open redirect vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2012-6072

больше 13 лет назад

CRLF injection vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-6071

почти 7 лет назад

nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-6070

почти 7 лет назад

Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-6063

почти 14 лет назад

Double free vulnerability in the sftp_mkdir function in sftp.c in libssh before 0.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors, a different vector than CVE-2012-4559.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-6062

больше 13 лет назад

The dissect_rtcp_app function in epan/dissectors/packet-rtcp.c in the RTCP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-6090

Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

CVSS2: 7.5
3%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-6089

Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

CVSS2: 7.5
4%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-6088

The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package.

CVSS2: 4.3
2%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-6087

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

CVSS2: 5.8
1%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-6086

libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc1, and 2.1.x before 2.1.2 does not properly set the CURLOPT_SSL_VERIFYHOST option for libcurl, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-6085

The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corrupt the public keyring database or cause a denial of service (application crash) via a crafted length field of an OpenPGP packet.

CVSS2: 5.8
3%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-6084

modules/m_capab.c in (1) ircd-ratbox before 3.0.8 and (2) Charybdis before 3.4.2 does not properly support capability negotiation during server handshakes, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed request.

CVSS2: 5
3%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-6083

Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.

CVSS3: 7.5
12%
Средний
больше 6 лет назад
ubuntu логотип
CVE-2012-6082

Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.

CVSS2: 4.3
2%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-6081

Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as exploited in the wild in July 2012.

CVSS2: 6
31%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2012-6080

Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a file name.

CVSS2: 6.4
4%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-6076

Inkscape before 0.48.4 reads .eps files from /tmp instead of the current directory, which might cause Inkspace to process unintended files, allow local users to obtain sensitive information, and possibly have other unspecified impacts.

CVSS2: 4.4
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-6075

Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.

CVSS2: 9.3
5%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-6074

Cross-site scripting (XSS) vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote authenticated users with write access to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 3.5
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-6073

Open redirect vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS2: 5.8
2%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-6072

CRLF injection vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS2: 4.3
2%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-6071

nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-6070

Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks.

CVSS3: 7.5
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-6063

Double free vulnerability in the sftp_mkdir function in sftp.c in libssh before 0.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors, a different vector than CVE-2012-4559.

CVSS2: 7.5
4%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-6062

The dissect_rtcp_app function in epan/dissectors/packet-rtcp.c in the RTCP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

CVSS2: 5
3%
Низкий
больше 13 лет назад

Уязвимостей на страницу