Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 4.2.x before 4.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPL-44614.
Published Jan 3, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application.
Published Jan 25, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in the HP-ChaiSOE/1.0 web server on the HP LaserJet P3015 printer with firmware before 07.080.3, LaserJet 4650 printer with firmware 07.006.0, and LaserJet 2430 printer with firmware 08.113.0_I35128 allows remote attackers to read arbitrary files via unspecified vectors, a different vulnerability than CVE-2008-4419.
Published Jan 10, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The AnGuanJia (com.anguanjia.safe) application 2.10.343 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application.
Published Jan 25, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application.
Published Jan 25, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does not support authentication, which allows remote attackers to (1) read arbitrary files via a management-console session that leverages the ability to create crafted data sources, or (2) execute management commands via an HTTP request.
Published Jan 3, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python classes, which allows remote authenticated administrators to execute arbitrary code by leveraging the sys module in a request to the search application, as demonstrated by a cross-site request forgery (CSRF) attack, aka SPL-45172.
Published Jan 3, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The create_pit_timer function in arch/x86/kvm/i8254.c in KVM 83, and possibly other versions, does not properly handle when Programmable Interval Timer (PIT) interrupt requests (IRQs) when a virtual interrupt controller (irqchip) is not available, which allows local users to cause a denial of service (NULL pointer dereference) by starting a timer.
Published Jan 27, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitrary files via a .. (dot dot) in a URI to (1) Splunk Web or (2) the Splunkd HTTP Server, aka SPL-45243.
Published Jan 3, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.
Published Jan 24, 2013 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
Published Jan 6, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The SSL 3.0 implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly initialize data structures for block cipher padding, which might allow remote attackers to obtain sensitive information by decrypting the padding data sent by an SSL peer.
Published Jan 6, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the HTML-Template-Pro module before 0.9507 for Perl allows remote attackers to inject arbitrary web script or HTML via template parameters, related to improper handling of > (greater than) and < (less than) characters.
Published Jan 6, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide malicious content, hijack sessions, and steal credentials by registering from an external vhost that does not enforce security constraints.
Published Jan 27, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Pretty-Link WordPress plugin 1.5.2 has XSS
Published Jan 10, 2020 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and regex parameters.
Published Jan 27, 2020 · Updated Aug 7, 2024
Unknown · CVSS Not scored
OpenSSL before 0.9.8s and 1.x before 1.0.0f, when RFC 3779 support is enabled, allows remote attackers to cause a denial of service (assertion failure) via an X.509 certificate containing certificate-extension data associated with (1) IP address blocks or (2) Autonomous System (AS) identifiers.
Published Jan 6, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4373.
Published Jan 10, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.
Published Jan 8, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Integer overflow in Adobe Reader 9.x before 9.4.6 on Linux allows attackers to execute arbitrary code via unspecified vectors.
Published Jan 19, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4372.
Published Jan 10, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
Published Jan 10, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.
Published Jan 8, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4372 and CVE-2011-4373.
Published Jan 10, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple handshake attempts.
Published Jan 27, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
websitebaker prior to and including 2.8.1 has an authentication error in backup module.
Published Jan 21, 2020 · Updated Aug 7, 2024
Unknown · CVSS Not scored
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.
Published Jan 27, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the desktop screen between SPICE sessions, which allows local users with access to a virtual machine to gain access to other users' desktop sessions via unspecified vectors.
Published Jan 4, 2013 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
Published Jan 15, 2020 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The NFS implementation in Linux kernel before 2.6.31-rc6 calls certain functions without properly initializing certain data, which allows local users to cause a denial of service (NULL pointer dereference and O_DIRECT oops), as demonstrated using diotest4 from LTP.
Published Jan 27, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in the hfs_mac2asc function in fs/hfs/trans.c in the Linux kernel 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via an HFS image with a crafted len field.
Published Jan 27, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.
Published Jan 3, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2.6 allows local users to cause a denial of service (assertion error and kernel oops) via an ext3 or ext4 image with an "invalid log first block value."
Published Jan 27, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files.
Published Jan 31, 2020 · Updated Aug 7, 2024
Unknown · CVSS Not scored
_is_safe in the File::Temp module for Perl does not properly handle symlinks.
Published Jan 31, 2020 · Updated Aug 7, 2024
Unknown · CVSS Not scored
PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sdl.c, ext/standard/syslog.c, ext/standard/browscap.c, ext/oci8/oci8.c, ext/com_dotnet/com_typeinfo.c, and main/php_open_temporary_file.c.
Published Jan 18, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Double free vulnerability in OpenSSL 0.9.8 before 0.9.8s, when X509_V_FLAG_POLICY_CHECK is enabled, allows remote attackers to have an unspecified impact by triggering failure of a policy check.
Published Jan 6, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which allows local users to overwrite files when another user extracts a PAR packed program. NOTE: a similar vulnerability was reported for PAR, but this has been assigned a different CVE identifier.
Published Jan 13, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The user_update function in security/keys/user_defined.c in the Linux kernel 2.6 allows local users to cause a denial of service (NULL pointer dereference and kernel oops) via vectors related to a user-defined key and "updating a negative key into a fully instantiated key."
Published Jan 27, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.
Published Jan 31, 2020 · Updated Aug 7, 2024
Unknown · CVSS Not scored
The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.
Published Jan 6, 2012 · Updated Aug 7, 2024
Unknown · CVSS Not scored
Jara 1.6 has a SQL injection vulnerability.
Published Jan 21, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Jara 1.6 has an XSS vulnerability
Published Jan 21, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ABRT might allow attackers to obtain sensitive information from crash reports.
Published Jan 31, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the WebClient ActiveX control in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to execute arbitrary code via a long string in a parameter associated with the location URL.
Published Jan 8, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when CONFIG_XFS_DEBUG is disabled, allows local users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an XFS image containing a symbolic link with a long pathname.
Published Jan 27, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Use-after-free vulnerability in Google Chrome before 16.0.912.77 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to DOM handling.
Published Jan 24, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Use-after-free vulnerability in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving animation frames.
Published Jan 7, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Published Jan 7, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Skia, as used in Google Chrome before 16.0.912.77, does not perform all required initialization of values, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Published Jan 24, 2012 · Updated Aug 6, 2024