VYPR

CVEs

386,806 total · page 6658 of 7,737

  • CVE-2012-5516Jan 4, 2013
    risk 0.00cvss —epss 0.00

    Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when moving disks between storage domains, does not properly wipe-after-delete, which prevents disks from being securely deleted and might allow local users to obtain sensitive information via unspecified vectors.

  • CVE-2012-4574Jan 4, 2013
    risk 0.00cvss —epss 0.00

    Pulp in Red Hat CloudForms before 1.1 uses world-readable permissions for pulp.conf, which allows local users to read the administrative password by reading this file.

  • CVE-2012-4556Jan 4, 2013
    risk 0.00cvss —epss 0.01

    The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 allows remote attackers to cause a denial of service (Apache httpd web server child process restart) via certain unspecified empty search fields in a user certificate search query.

  • CVE-2012-4555Jan 4, 2013
    risk 0.00cvss —epss 0.01

    The token processing system (pki-tps) in Red Hat Certificate System (RHCS) before 8.1.3 does not properly handle interruptions of token format operations, which allows remote attackers to cause a denial of service (NULL pointer dereference and Apache httpd web server child…

  • CVE-2012-4543Jan 4, 2013
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) pageStart or (2) pageSize to the displayCRL script, or (3) nonce variable to the profileProcess script.

  • CVE-2012-3538Jan 4, 2013
    risk 0.00cvss —epss 0.01

    Pulp in Red Hat CloudForms before 1.1 logs administrative passwords in a world-readable file, which allows local users to read pulp administrative passwords by reading production.log.

  • CVE-2012-2696Jan 4, 2013
    risk 0.00cvss —epss 0.01

    The backend in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1 does not properly check privileges, which allows remote authenticated users to query arbitrary information via a (1) SOAP or (2) GWT request.

  • CVE-2012-0861Jan 4, 2013
    risk 0.00cvss —epss 0.01

    The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vds_bootstrap.py, which prevents SSL certificates from being validated and allows remote attackers to execute…

  • CVE-2012-0860Jan 4, 2013
    risk 0.00cvss —epss 0.00

    Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local users to gain privileges via a Trojan horse (1) deployUtil.py or (2) vds_bootstrap.py Python module in /tmp/.

  • CVE-2011-4316Jan 4, 2013
    risk 0.00cvss —epss 0.00

    Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the desktop screen between SPICE sessions, which allows local users with access to a virtual machine to gain access to other users' desktop sessions via unspecified…

  • CVE-2012-6348Jan 4, 2013
    risk 0.00cvss —epss 0.00

    Centrify Deployment Manager 2.1.0.283, as distributed in Centrify Suite before 2012.5, allows local users to (1) overwrite arbitrary files via a symlink attack on the adcheckDMoutput temporary file, or (2) overwrite arbitrary files and consequently gain privileges via a symlink…

  • CVE-2012-6330Jan 4, 2013
    risk 0.06cvss —epss 0.36

    The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consumption) via a large integer in a %MAKETEXT% macro.

  • CVE-2012-6329Jan 4, 2013
    risk 0.01cvss —epss 0.64

    The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly handle backslashes and fully qualified method names during compilation of bracket notation, which allows context-dependent attackers to execute arbitrary commands…

  • CVE-2012-5977Jan 4, 2013
    risk 0.00cvss —epss 0.02

    Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones, when anonymous calls are enabled, allow remote attackers to cause a…

  • CVE-2012-6090Jan 4, 2013
    risk 0.00cvss —epss 0.03

    Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

  • CVE-2012-6089Jan 4, 2013
    risk 0.00cvss —epss 0.04

    Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted filename.

  • CVE-2012-5976Jan 4, 2013
    risk 0.00cvss —epss 0.03

    Multiple stack consumption vulnerabilities in Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Asterisk 1.8.11 before 1.8.11-cert10; and Asterisk Digiumphones 10.x-digiumphones before 10.11.1-digiumphones allow remote attackers…

  • CVE-2012-6497Jan 4, 2013
    risk 0.00cvss —epss 0.03

    The Authlogic gem for Ruby on Rails, when used with certain versions before 3.2.10, makes potentially unsafe find_by_id method calls, which might allow remote attackers to conduct CVE-2012-6496 SQL injection attacks via a crafted parameter in environments that have a known…

  • CVE-2012-6496Jan 4, 2013
    risk 0.00cvss —epss 0.05

    SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in…

  • CVE-2012-6434Jan 3, 2013
    risk 0.03cvss —epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) download_url, (2) download_url_extended, (3)…

  • CVE-2012-6433Jan 3, 2013
    risk 0.03cvss —epss 0.02

    Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hijack the authentication of administrators for requests that conduct XSS attacks via the news_title parameter in a create action.

  • CVE-2012-5667Jan 3, 2013
    risk 0.00cvss —epss 0.01

    Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via vectors involving a long input line that triggers a heap-based buffer overflow.

  • CVE-2012-6495Jan 3, 2013
    risk 0.04cvss —epss 0.19

    Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to overwrite arbitrary files via unspecified vectors. …

  • CVE-2012-6082Jan 3, 2013
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.

  • CVE-2012-6081Jan 3, 2013
    risk 0.00cvss —epss 0.35

    Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an…

  • CVE-2012-6080Jan 3, 2013
    risk 0.00cvss —epss 0.04

    Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a file name.

  • CVE-2012-5666Jan 3, 2013
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in bookmarks/js/bookmarks.js in ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to apps/bookmark/index.php.

  • CVE-2012-5665Jan 3, 2013
    risk 0.00cvss —epss 0.02

    ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 does not properly restrict access to settings.php, which allows remote attackers to edit app configurations of user_webdavauth and user_ldap by editing this file.

  • CVE-2012-5655Jan 3, 2013
    risk 0.00cvss —epss 0.02

    The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allows remote attackers to obtain sensitive information via a crafted request.

  • CVE-2012-5654Jan 3, 2013
    risk 0.00cvss —epss 0.01

    The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to obtain sensitive information by reading…

  • CVE-2012-5653Jan 3, 2013
    risk 0.00cvss —epss 0.02

    The file upload feature in Drupal 6.x before 6.27 and 7.x before 7.18 allows remote authenticated users to bypass the protection mechanism and execute arbitrary PHP code via a null byte in a file name.

  • CVE-2012-5652Jan 3, 2013
    risk 0.00cvss —epss 0.02

    Drupal 6.x before 6.27 allows remote attackers to obtain sensitive information about uploaded files via a (1) RSS feed or (2) search result.

  • CVE-2012-5651Jan 3, 2013
    risk 0.00cvss —epss 0.03

    Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information by reading the search results.

  • CVE-2012-4545Jan 3, 2013
    risk 0.00cvss —epss 0.02

    The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the…

  • CVE-2012-2379Jan 3, 2013
    risk 0.00cvss —epss 0.04

    Apache CXF 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1, when a Supporting Token specifies a child WS-SecurityPolicy 1.1 or 1.2 policy, does not properly ensure that an XML element is signed or encrypted, which has unspecified impact and attack vectors.

  • CVE-2013-0721Jan 2, 2013
    risk 0.00cvss —epss 0.02

    wp-php-widget.php in the WP PHP widget plugin 1.0.2 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

  • CVE-2012-6472Jan 2, 2013
    risk 0.00cvss —epss 0.00

    Opera before 12.12 on UNIX uses weak permissions for the profile directory, which allows local users to obtain sensitive information by reading a (1) cache file, (2) password file, or (3) configuration file, or (4) possibly gain privileges by modifying or overwriting a…

  • CVE-2012-6471Jan 2, 2013
    risk 0.00cvss —epss 0.01

    Opera before 12.12 allows remote attackers to spoof the address field via a high rate of HTTP requests.

  • CVE-2012-6470Jan 2, 2013
    risk 0.04cvss —epss 0.08

    Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a malformed image.

  • CVE-2012-6469Jan 2, 2013
    risk 0.00cvss —epss 0.01

    Opera before 12.11 allows remote attackers to determine the existence of arbitrary local files via vectors involving web script in an error page.

  • CVE-2012-6468Jan 2, 2013
    risk 0.00cvss —epss 0.04

    Heap-based buffer overflow in Opera before 12.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a long HTTP response.

  • CVE-2012-6467Jan 2, 2013
    risk 0.00cvss —epss 0.01

    Opera before 12.10 follows Internet shortcuts that are referenced by a (1) IMG element or (2) other inline element, which makes it easier for remote attackers to conduct phishing attacks via a crafted web site, as exploited in the wild in November 2012.

  • CVE-2012-6466Jan 2, 2013
    risk 0.00cvss —epss 0.02

    Opera before 12.10 does not properly handle incorrect size data in a WebP image, which allows remote attackers to obtain potentially sensitive information from process memory by using a crafted image as the fill pattern for a canvas.

  • CVE-2012-6465Jan 2, 2013
    risk 0.00cvss —epss 0.04

    Opera before 12.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed SVG image.

  • CVE-2012-6464Jan 2, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript code that overrides methods of unspecified native objects in documents that have different origins.

  • CVE-2012-6463Jan 2, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Opera before 12.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an unspecified sequence of loading of documents and loading of data: URLs.

  • CVE-2012-6462Jan 2, 2013
    risk 0.00cvss —epss 0.02

    Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remote attackers to bypass intended page-content restrictions via a crafted request.

  • CVE-2012-6461Jan 2, 2013
    risk 0.00cvss —epss 0.01

    The X.509 certificate-validation functionality in the https implementation in Opera before 12.10 allows remote attackers to trigger a false indication of successful revocation-status checking by causing a failure of a single checking service.

  • CVE-2012-6460Jan 2, 2013
    risk 0.00cvss —epss 0.02

    Opera before 11.67 and 12.x before 12.02 allows remote attackers to cause truncation of a dialog, and possibly trigger downloading and execution of arbitrary programs, via a crafted web site.

  • CVE-2012-6459Jan 1, 2013
    risk 0.00cvss —epss 0.01

    ConnMan 1.3 on Tizen continues to list the bluetooth service after offline mode has been enabled, which might allow remote attackers to obtain sensitive information via Bluetooth packets.