Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 76 769

Количество 76 769

ubuntu логотип

CVE-2012-3364

больше 13 лет назад

Multiple stack-based buffer overflows in the Near Field Communication Controller Interface (NCI) in the Linux kernel before 3.4.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via incoming frames with crafted length fields.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-3363

больше 13 лет назад

Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.

CVSS3: 9.1
EPSS: Средний
ubuntu логотип

CVE-2012-3362

около 14 лет назад

Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an adduser admin action.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-3361

около 14 лет назад

virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-3360

около 14 лет назад

Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a .. (dot dot) in the path attribute of a file element.

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-3358

около 14 лет назад

Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted (1) tile number or (2) tile length in a JPEG 2000 image file.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2012-3357

около 14 лет назад

The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information, related to a "log msg leak."

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-3356

около 14 лет назад

The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-3355

около 14 лет назад

(1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory.

CVSS2: 3.6
EPSS: Низкий
ubuntu логотип

CVE-2012-3354

почти 14 лет назад

doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-3345

около 14 лет назад

ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file.

CVSS2: 5.6
EPSS: Низкий
ubuntu логотип

CVE-2012-3342

больше 13 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2012-3334

почти 14 лет назад

Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION statement.

CVSS2: 9
EPSS: Низкий
ubuntu логотип

CVE-2012-3324

почти 14 лет назад

Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to modify, delete, or read arbitrary files via a pathname in the file field.

CVSS2: 9
EPSS: Низкий
ubuntu логотип

CVE-2012-3292

около 14 лет назад

The GridFTP in Globus Toolkit (GT) before 5.2.2, when certain autoconf macros are defined, does not properly check the return value from the getpwnam_r function, which might allow remote attackers to gain privileges by logging in with a user that does not exist, which causes GridFTP to run as the last user in the password file.

CVSS2: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2012-3291

около 14 лет назад

Heap-based buffer overflow in OpenConnect 3.18 allows remote servers to cause a denial of service via a crafted greeting banner.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2012-3287

около 14 лет назад

Poul-Henning Kamp md5crypt has insufficient algorithmic complexity and a consequently short runtime, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack, as demonstrated by an attack using GPU hardware.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-3241

около 14 лет назад

The VMware Broker in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 does not properly authenticate SOAP requests, which allows remote attackers to execute arbitrary VMware Broker API commands.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-3240

около 14 лет назад

The Walrus service in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 allows remote attackers to gain administrator privileges via a crafted REST request.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-3236

около 14 лет назад

fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.

CVSS2: 4.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-3364

Multiple stack-based buffer overflows in the Near Field Communication Controller Interface (NCI) in the Linux kernel before 3.4.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via incoming frames with crafted length fields.

CVSS2: 5
5%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-3363

Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.

CVSS3: 9.1
50%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2012-3362

Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an adduser admin action.

CVSS2: 6.8
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3361

virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.

CVSS2: 5.5
3%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3360

Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a .. (dot dot) in the path attribute of a file element.

CVSS2: 5.5
3%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3358

Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted (1) tile number or (2) tile length in a JPEG 2000 image file.

CVSS2: 10
8%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3357

The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information, related to a "log msg leak."

CVSS2: 5
2%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3356

The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

CVSS2: 5
2%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3355

(1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory.

CVSS2: 3.6
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3354

doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message.

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-3345

ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file.

CVSS2: 5.6
0%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3342

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than other CVEs listed in the February 2013 CPU.

CVSS2: 10
8%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-3334

Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION statement.

CVSS2: 9
4%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-3324

Directory traversal vulnerability in the UTL_FILE module in IBM DB2 and DB2 Connect 10.1 before FP1 on Windows allows remote authenticated users to modify, delete, or read arbitrary files via a pathname in the file field.

CVSS2: 9
4%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-3292

The GridFTP in Globus Toolkit (GT) before 5.2.2, when certain autoconf macros are defined, does not properly check the return value from the getpwnam_r function, which might allow remote attackers to gain privileges by logging in with a user that does not exist, which causes GridFTP to run as the last user in the password file.

CVSS2: 7.6
3%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3291

Heap-based buffer overflow in OpenConnect 3.18 allows remote servers to cause a denial of service via a crafted greeting banner.

CVSS2: 7.8
2%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3287

Poul-Henning Kamp md5crypt has insufficient algorithmic complexity and a consequently short runtime, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack, as demonstrated by an attack using GPU hardware.

CVSS2: 5
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3241

The VMware Broker in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 does not properly authenticate SOAP requests, which allows remote attackers to execute arbitrary VMware Broker API commands.

CVSS2: 7.5
2%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3240

The Walrus service in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 allows remote attackers to gain administrator privileges via a crafted REST request.

CVSS2: 7.5
2%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-3236

fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.

CVSS2: 4.3
11%
Средний
около 14 лет назад

Уязвимостей на страницу