Total
307662 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2012-5878 | 1 Bulbsecurity | 1 Smartphone Pentest Framework | 2024-11-21 | 10.0 HIGH | 9.8 CRITICAL |
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl. | |||||
CVE-2012-5867 | 1 Ht Editor Project | 1 Ht Editor | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
HT Editor 2.0.20 has a Remote Stack Buffer Overflow Vulnerability | |||||
CVE-2012-5828 | 1 Blackberry | 2 Playbook, Playbook Firmware | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error | |||||
CVE-2012-5776 | 1 Dokeos | 1 Dokeos | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php. | |||||
CVE-2012-5699 | 1 Babygekko | 1 Babygekko | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
BabyGekko before 1.2.4 allows PHP file inclusion. | |||||
CVE-2012-5698 | 1 Babygekko | 1 Babygekko | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
BabyGekko before 1.2.4 has SQL injection. | |||||
CVE-2012-5693 | 1 Bulbsecurity | 1 Smartphone Pentest Framework | 2024-11-21 | 8.3 HIGH | 8.8 HIGH |
Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) remoteAttack.pl or (2) guessPassword.pl in frameworkgui/; the filename parameter to (3) CSAttack.pl or (4) SEAttack.pl in frameworkgui/; the phNo2Attack parameter to (5) CSAttack.pl or (6) SEAttack.pl in frameworkgui/; the (7) platformDD2 parameter to frameworkgui/SEAttack.pl; the (8) agentURLPath or (9) agentControlKey parameter to frameworkgui/attach2agents.pl; or the (10) controlKey parameter to frameworkgui/attachMobileModem.pl. NOTE: The hostingPath parameter to CSAttack.pl and SEAttack.pl vectors and the appURLPath parameter to attachMobileModem.pl vector are covered by CVE-2012-5878. | |||||
CVE-2012-5686 | 1 Zpanelcp | 1 Zpanel | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
ZPanel 10.0.1 has insufficient entropy for its password reset process. | |||||
CVE-2012-5663 | 1 Openbsd | 1 Textproc\/isearch | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp). | |||||
CVE-2012-5645 | 2 Fedoraproject, Freeciv | 2 Fedora, Freeciv | 2024-11-21 | 7.8 HIGH | 7.5 HIGH |
A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption. | |||||
CVE-2012-5644 | 4 Debian, Fedoraproject, Libuser Project and 1 more | 4 Debian Linux, Fedora, Libuser and 1 more | 2024-11-21 | 4.9 MEDIUM | 5.5 MEDIUM |
libuser has information disclosure when moving user's home directory | |||||
CVE-2012-5640 | 1 Acme | 1 Thttpd | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
thttpd has a local DoS vulnerability via specially-crafted .htpasswd files | |||||
CVE-2012-5639 | 3 Apache, Debian, Libreoffice | 3 Openoffice, Debian Linux, Libreoffice | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
LibreOffice and OpenOffice automatically open embedded content | |||||
CVE-2012-5631 | 1 Freeipa | 1 Freeipa | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
ipa 3.0 does not properly check server identity before sending credential containing cookies | |||||
CVE-2012-5630 | 3 Fedoraproject, Libuser Project, Redhat | 3 Fedora, Libuser, Enterprise Linux | 2024-11-21 | 3.3 LOW | 6.3 MEDIUM |
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees. | |||||
CVE-2012-5628 | 1 Gofer Project | 1 Gofer | 2024-11-21 | 3.6 LOW | 4.4 MEDIUM |
gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries. | |||||
CVE-2012-5626 | 1 Redhat | 6 Jboss Brms, Jboss Enterprise Application Platform, Jboss Enterprise Web Server and 3 more | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation. | |||||
CVE-2012-5623 | 1 Squirrelmail | 1 Change Passwd | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords. | |||||
CVE-2012-5618 | 1 Ushahidi | 1 Ushahidi | 2024-11-21 | 5.0 MEDIUM | 9.8 CRITICAL |
Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens. | |||||
CVE-2012-5617 | 2 Fedoraproject, Gksu-polkit Project | 2 Fedora, Gksu-polkit | 2024-11-21 | 7.2 HIGH | 7.8 HIGH |
gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation |