Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 76 769

Количество 76 769

ubuntu логотип

CVE-2012-0845

почти 14 лет назад

SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an XML-RPC POST request that contains a smaller amount of data than specified by the Content-Length header.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-0844

больше 6 лет назад

Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0843

почти 7 лет назад

uzbl: Information disclosure via world-readable cookies storage file

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0842

почти 7 лет назад

surf: cookie jar has read access from other local user

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0841

больше 13 лет назад

libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-0840

больше 14 лет назад

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2012-0839

больше 14 лет назад

OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-0838

больше 14 лет назад

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2012-0834

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-0833

около 14 лет назад

The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.

CVSS2: 2.3
EPSS: Низкий
ubuntu логотип

CVE-2012-0831

больше 14 лет назад

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0830

больше 14 лет назад

The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2012-0827

почти 13 лет назад

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0826

почти 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0825

почти 13 лет назад

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0824

почти 7 лет назад

gnusound 0.7.5 has format string issue

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0823

больше 14 лет назад

VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting decoding from a P-frame," which triggers an out-of-bounds read, related to "the clamping of motion vectors in SPLITMV blocks".

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-0817

больше 14 лет назад

Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-0815

около 14 лет назад

The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0814

больше 14 лет назад

The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by reading these messages, as demonstrated by the shared user account required by Gitolite. NOTE: this can cross privilege boundaries because a user account may intentionally have no shell or filesystem access, and therefore may have no supported way to read an authorized_keys file in its own home directory.

CVSS2: 3.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-0845

SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an XML-RPC POST request that contains a smaller amount of data than specified by the Content-Length header.

CVSS2: 5
5%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-0844

Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.

CVSS3: 5.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2012-0843

uzbl: Information disclosure via world-readable cookies storage file

CVSS3: 5.5
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-0842

surf: cookie jar has read access from other local user

CVSS3: 5.5
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-0841

libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.

CVSS2: 5
3%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-0840

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

CVSS2: 5
43%
Средний
больше 14 лет назад
ubuntu логотип
CVE-2012-0839

OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

CVSS2: 5
3%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2012-0838

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.

CVSS2: 10
14%
Средний
больше 14 лет назад
ubuntu логотип
CVE-2012-0834

Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.

CVSS2: 4.3
5%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2012-0833

The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.

CVSS2: 2.3
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-0831

PHP before 5.3.10 does not properly perform a temporary change to the magic_quotes_gpc directive during the importing of environment variables, which makes it easier for remote attackers to conduct SQL injection attacks via a crafted request, related to main/php_variables.c, sapi/cgi/cgi_main.c, and sapi/fpm/fpm/fpm_main.c.

CVSS2: 6.8
7%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2012-0830

The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.

CVSS2: 7.5
30%
Средний
больше 14 лет назад
ubuntu логотип
CVE-2012-0827

The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.

CVSS2: 3.5
1%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-0826

Cross-site request forgery (CSRF) vulnerability in the Aggregator module in Drupal 6.x before 6.23 and 7.x before 7.11 allows remote attackers to hijack the authentication of unspecified victims for requests that update feeds and possibly cause a denial of service (loss of updates due to rate limit) via unspecified vectors.

CVSS2: 6.8
1%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.

CVSS2: 6.8
2%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-0824

gnusound 0.7.5 has format string issue

CVSS3: 9.8
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2012-0823

VP8 Codec SDK (libvpx) before 1.0.0 "Duclair" allows remote attackers to cause a denial of service (application crash) via (1) unspecified "corrupt input" or (2) by "starting decoding from a P-frame," which triggers an out-of-bounds read, related to "the clamping of motion vectors in SPLITMV blocks".

CVSS2: 5
3%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2012-0817

Memory leak in smbd in Samba 3.6.x before 3.6.3 allows remote attackers to cause a denial of service (memory and CPU consumption) by making many connection requests.

CVSS2: 5
4%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2012-0815

The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.

CVSS2: 6.8
4%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-0814

The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, which allows remote authenticated users to obtain potentially sensitive information by reading these messages, as demonstrated by the shared user account required by Gitolite. NOTE: this can cross privilege boundaries because a user account may intentionally have no shell or filesystem access, and therefore may have no supported way to read an authorized_keys file in its own home directory.

CVSS2: 3.5
4%
Низкий
больше 14 лет назад

Уязвимостей на страницу