Total
31683 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-2258 | 1 Cryptocat Project | 1 Cryptocat | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
Cryptocat before 2.0.22 has Nickname User Impersonation | |||||
CVE-2013-2097 | 1 Zpanel Project | 1 Zpanel | 2024-11-21 | 9.3 HIGH | 7.8 HIGH |
ZPanel through 10.1.0 has Remote Command Execution | |||||
CVE-2013-20001 | 1 Openzfs | 1 Openzfs | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data, and access is allowed to everyone. IPv6 restrictions from the configuration are not applied. | |||||
CVE-2013-1753 | 1 Python | 1 Python | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request. | |||||
CVE-2013-1744 | 1 Iris Citations Management Tool Project | 1 Iris Citations Management Tool | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands. | |||||
CVE-2012-6613 | 1 Dlink | 2 Dsr-250n, Dsr-250n Firmware | 2024-11-21 | 9.0 HIGH | 7.2 HIGH |
D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account. | |||||
CVE-2012-6345 | 1 Novell | 1 Zenworks Configuration Management | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information. | |||||
CVE-2012-6309 | 1 Arctic Torrent Project | 1 Arctic Torrent | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
A vulnerability exists in Arctic Torrent 1.4 via unspecified vectors in .torrent file handling, which could let a malicious user cause a Denial of Service. | |||||
CVE-2012-6307 | 1 Impulseadventure | 1 Jpegsnoop | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious user execute arbitrary code | |||||
CVE-2012-6306 | 1 Hcview Project | 1 Hcview | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
A vulnerability exists in HCView (aka Hardcoreview) 1.4 due to a write access violation with a GIF file. | |||||
CVE-2012-6277 | 3 Hp, Ibm, Symantec | 7 Autonomy Keyview Idol, Domino, Notes and 4 more | 2024-11-21 | 9.3 HIGH | 7.8 HIGH |
Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code." | |||||
CVE-2012-5626 | 1 Redhat | 6 Jboss Brms, Jboss Enterprise Application Platform, Jboss Enterprise Web Server and 3 more | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation. | |||||
CVE-2012-4818 | 1 Ibm | 1 Infosphere Information Server | 2024-11-21 | N/A | 6.5 MEDIUM |
IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper restrictions on directories. An attacker could exploit this vulnerability via the DataStage application to load or import content functionality to view arbitrary files on the system. | |||||
CVE-2012-3810 | 1 Samsung | 1 Kies | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Samsung Kies before 2.5.0.12094_27_11 has registry modification. | |||||
CVE-2012-3809 | 1 Samsung | 1 Kies | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification. | |||||
CVE-2012-3808 | 1 Samsung | 1 Kies | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification. | |||||
CVE-2012-3807 | 1 Samsung | 1 Kies | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution. | |||||
CVE-2012-3490 | 1 Wisc | 1 Htcondor | 2024-11-21 | 9.0 HIGH | 8.8 HIGH |
The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the return value of setuid calls, which might cause a subprocess to be created with root privileges and allow remote attackers to gain privileges via unspecified vectors. | |||||
CVE-2012-2204 | 1 Ibm | 1 Infosphere Guardium | 2024-11-21 | 4.9 MEDIUM | 5.5 MEDIUM |
InfoSphere Guardium aix_ktap module: DoS | |||||
CVE-2012-2201 | 1 Ibm | 1 Websphere Mq | 2024-11-21 | N/A | 7.5 HIGH |
IBM WebSphere MQ 7.1 is vulnerable to a denial of service, caused by an error when handling user ids. A remote attacker could exploit this vulnerability to bypass the security configuration setup on a SVRCONN channel and flood the queue manager. |