Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 76 769

Количество 76 769

ubuntu логотип

CVE-2012-1170

почти 7 лет назад

Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough Versions 2.2 to 2.2.1+ affected.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-1169

почти 7 лет назад

Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs. Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+ affected.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2012-1168

почти 7 лет назад

Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+ affected.

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2012-1167

почти 14 лет назад

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2012-1166

больше 12 лет назад

The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2012-1165

больше 14 лет назад

The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-1164

около 14 лет назад

slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2012-1163

около 14 лет назад

Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to execute arbitrary code via the size and offset values for the central directory in a zip archive, which triggers "improper restrictions of operations within the bounds of a memory buffer" and an information leak.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-1162

около 14 лет назад

Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a zip archive with the number of directories set to 0, related to an "incorrect loop construct."

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-1161

почти 7 лет назад

Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+ affected.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-1160

почти 7 лет назад

Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+ affected.

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2012-1159

почти 7 лет назад

Moodle before 2.2.2: Overview report allows users to see hidden courses Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+ affected.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-1158

почти 7 лет назад

Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+ are affected.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-1157

почти 7 лет назад

Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+ are affected.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-1156

почти 7 лет назад

Moodle before 2.2.2 has users' private files included in course backups Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+ are affected.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-1155

почти 7 лет назад

Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+, 1.9 to 1.9.16+ are affected.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-1152

почти 14 лет назад

Multiple format string vulnerabilities in the error reporting functionality in the YAML::LibYAML (aka YAML-LibYAML and perl-YAML-LibYAML) module 0.38 for Perl allow remote attackers to cause a denial of service (process crash) via format string specifiers in a (1) YAML stream to the Load function, (2) YAML node to the load_node function, (3) YAML mapping to the load_mapping function, or (4) YAML sequence to the load_sequence function.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-1151

почти 14 лет назад

Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-1150

почти 14 лет назад

Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-1149

около 14 лет назад

Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-1170

Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough Versions 2.2 to 2.2.1+ affected.

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-1169

Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs. Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+ affected.

CVSS3: 5.3
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-1168

Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+ affected.

CVSS3: 8.2
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-1167

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.

CVSS2: 4.6
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-1166

The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.

CVSS2: 10
5%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-1165

The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.

CVSS2: 5
7%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2012-1164

slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.

CVSS2: 2.6
4%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-1163

Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to execute arbitrary code via the size and offset values for the central directory in a zip archive, which triggers "improper restrictions of operations within the bounds of a memory buffer" and an information leak.

CVSS2: 6.8
3%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-1162

Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a zip archive with the number of directories set to 0, related to an "incorrect loop construct."

CVSS2: 7.5
4%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-1161

Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+ affected.

CVSS3: 4.3
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-1160

Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+ affected.

CVSS3: 2.7
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-1159

Moodle before 2.2.2: Overview report allows users to see hidden courses Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+ affected.

CVSS3: 4.3
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-1158

Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+ are affected.

CVSS3: 4.3
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-1157

Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+ are affected.

CVSS3: 4.3
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-1156

Moodle before 2.2.2 has users' private files included in course backups Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+ are affected.

CVSS3: 7.5
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-1155

Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to Versions 2.2 to 2.2.1+, 2.1 to 2.1.4+, 2.0 to 2.0.7+, 1.9 to 1.9.16+ are affected.

CVSS3: 7.5
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-1152

Multiple format string vulnerabilities in the error reporting functionality in the YAML::LibYAML (aka YAML-LibYAML and perl-YAML-LibYAML) module 0.38 for Perl allow remote attackers to cause a denial of service (process crash) via format string specifiers in a (1) YAML stream to the Load function, (2) YAML node to the load_node function, (3) YAML mapping to the load_mapping function, or (4) YAML sequence to the load_sequence function.

CVSS2: 5
2%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-1151

Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.

CVSS2: 5
3%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-1150

Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

CVSS2: 5
5%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-1149

Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.

CVSS2: 7.5
14%
Средний
около 14 лет назад

Уязвимостей на страницу