Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 202

Количество 77 202

ubuntu логотип

CVE-2012-5568

почти 14 лет назад

Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-5567

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.18, as used in Horde Groupware Webmail Edition before 4.0.9, allow remote attackers to inject arbitrary web script or HTML via crafted event location parameters in the (1) month, (2) monthlist, or (3) prevmonthlist fields, related to portal blocks.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-5566

больше 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.17, as used in Horde Groupware Webmail Edition before 4.0.8, allow remote attackers to inject arbitrary web script or HTML via the (1) tasks view or (2) search view.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-5564

больше 13 лет назад

android-tools 4.1.1 in Android Debug Bridge (ADB) allows local users to overwrite arbitrary files via a symlink attack on /tmp/adb.log.

CVSS2: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2012-5563

больше 13 лет назад

OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-5535

почти 7 лет назад

gnome-system-log polkit policy allows arbitrary files on the system to be read

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5534

больше 13 лет назад

The hook_process function in the plugin API for WeeChat 0.3.0 through 0.3.9.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to "shell expansion."

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5533

почти 14 лет назад

The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2012-5532

больше 13 лет назад

The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2669.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2012-5530

почти 14 лет назад

The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2012-5529

почти 14 лет назад

TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5527

почти 7 лет назад

Claws Mail vCalendar plugin: credentials exposed on interface

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5526

почти 14 лет назад

CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-5525

больше 13 лет назад

The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service (crash) via a crafted GFN that triggers a buffer over-read.

CVSS2: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2012-5524

больше 12 лет назад

The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which allows remote attackers to conduct man-in-the-middle (MITM) attacks and spoof servers via an arbitrary certificate from a trusted CA.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-5523

почти 14 лет назад

core/email_api.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow remote authenticated users to obtain sensitive information by adding a note to a bug before losing permission to view that bug.

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5522

почти 14 лет назад

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5521

почти 7 лет назад

quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5519

почти 14 лет назад

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2012-5517

больше 13 лет назад

The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact in opportunistic circumstances by using memory that was hot-added by an administrator.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-5568

Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

CVSS2: 5
10%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5567

Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.18, as used in Horde Groupware Webmail Edition before 4.0.9, allow remote attackers to inject arbitrary web script or HTML via crafted event location parameters in the (1) month, (2) monthlist, or (3) prevmonthlist fields, related to portal blocks.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-5566

Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.17, as used in Horde Groupware Webmail Edition before 4.0.8, allow remote attackers to inject arbitrary web script or HTML via the (1) tasks view or (2) search view.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-5564

android-tools 4.1.1 in Android Debug Bridge (ADB) allows local users to overwrite arbitrary files via a symlink attack on /tmp/adb.log.

CVSS2: 3.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5563

OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.

CVSS2: 4
3%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5535

gnome-system-log polkit policy allows arbitrary files on the system to be read

CVSS3: 7.5
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-5534

The hook_process function in the plugin API for WeeChat 0.3.0 through 0.3.9.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to "shell expansion."

CVSS2: 7.5
4%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5533

The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.

CVSS2: 5
12%
Средний
почти 14 лет назад
ubuntu логотип
CVE-2012-5532

The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2669.

CVSS2: 4.9
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5530

The (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink attack on a /var/tmp/##### temporary file.

CVSS2: 2.1
0%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5529

TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query.

CVSS2: 3.5
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5527

Claws Mail vCalendar plugin: credentials exposed on interface

CVSS3: 5.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-5526

CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into responses from applications that use CGI.pm.

CVSS2: 5
3%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5525

The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service (crash) via a crafted GFN that triggers a buffer over-read.

CVSS2: 4.7
2%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5524

The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which allows remote attackers to conduct man-in-the-middle (MITM) attacks and spoof servers via an arbitrary certificate from a trusted CA.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-5523

core/email_api.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow remote authenticated users to obtain sensitive information by adding a note to a bug before losing permission to view that bug.

CVSS2: 5.5
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5522

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remote authenticated users to bypass intended access restrictions and make status changes by leveraging a blank value for a per-status setting.

CVSS2: 5.5
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5521

quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal

CVSS3: 6.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-5519

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.

CVSS2: 7.2
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-5517

The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact in opportunistic circumstances by using memory that was hot-added by an administrator.

CVSS2: 4
0%
Низкий
больше 13 лет назад

Уязвимостей на страницу