Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 202

Количество 77 202

ubuntu логотип

CVE-2012-5645

больше 6 лет назад

A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5644

почти 7 лет назад

libuser has information disclosure when moving user's home directory

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5643

больше 13 лет назад

Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2012-5642

больше 13 лет назад

server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to trigger unsafe behavior in a custom action file via unspecified symbols in this content.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5641

больше 12 лет назад

Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the default URI.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-5639

больше 6 лет назад

LibreOffice and OpenOffice automatically open embedded content

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5638

больше 13 лет назад

The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.

CVSS2: 3.6
EPSS: Низкий
ubuntu логотип

CVE-2012-5635

больше 13 лет назад

The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2012-5634

больше 13 лет назад

Xen 4.2.x, 4.1.x, and 4.0, when using Intel VT-d for PCI passthrough, does not properly configure VT-d when supporting a device that is behind a legacy PCI Bridge, which allows local guests to cause a denial of service to other guests by injecting an interrupt.

CVSS2: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2012-5633

больше 13 лет назад

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2012-5631

почти 7 лет назад

ipa 3.0 does not properly check server identity before sending credential containing cookies

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2012-5630

почти 7 лет назад

libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2012-5629

больше 13 лет назад

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5627

почти 13 лет назад

Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

CVSS2: 4
EPSS: Средний
ubuntu логотип

CVE-2012-5626

больше 6 лет назад

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5625

больше 13 лет назад

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-5624

больше 13 лет назад

The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-5621

почти 12 лет назад

lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection with a party name that contains invalid UTF-8 strings.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-5620

больше 6 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
ubuntu логотип

CVE-2012-5619

почти 12 лет назад

The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activities, as demonstrated by Flame.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-5645

A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption.

CVSS3: 7.5
4%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2012-5644

libuser has information disclosure when moving user's home directory

CVSS3: 5.5
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-5643

Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.

CVSS2: 5
23%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2012-5642

server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to trigger unsafe behavior in a custom action file via unspecified symbols in this content.

CVSS2: 7.5
3%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5641

Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the default URI.

CVSS2: 5
9%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-5639

LibreOffice and OpenOffice automatically open embedded content

CVSS3: 6.5
6%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2012-5638

The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.

CVSS2: 3.6
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5635

The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S30samba-stop.sh, and possibly other vectors, different vulnerabilities than CVE-2012-4417.

CVSS2: 2.1
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5634

Xen 4.2.x, 4.1.x, and 4.0, when using Intel VT-d for PCI passthrough, does not properly configure VT-d when supporting a device that is behind a legacy PCI Bridge, which allows local guests to cause a denial of service to other guests by injecting an interrupt.

CVSS2: 6.1
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5633

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Security processing, which allows remote attackers to obtain access to SOAP services via an HTTP GET request.

CVSS2: 5.8
8%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5631

ipa 3.0 does not properly check server identity before sending credential containing cookies

CVSS3: 8.8
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-5630

libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.

CVSS3: 6.3
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-5629

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

CVSS2: 7.5
2%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5627

Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

CVSS2: 4
11%
Средний
почти 13 лет назад
ubuntu логотип
CVE-2012-5626

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.

CVSS3: 7.5
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2012-5625

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by reading the memory of the previous logical volume (LV).

CVSS2: 4.3
2%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5624

The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.

CVSS2: 4.3
2%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5621

lib/engine/components/opal/opal-call.cpp in ekiga before 4.0.0 allows remote attackers to cause a denial of service (crash) via an OPAL connection with a party name that contains invalid UTF-8 strings.

CVSS2: 5
3%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2012-5620

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

больше 6 лет назад
ubuntu логотип
CVE-2012-5619

The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activities, as demonstrated by Flame.

CVSS2: 2.1
0%
Низкий
почти 12 лет назад

Уязвимостей на страницу