Search Results (23782 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-0291 1 Imagely 1 Nextgen Gallery 2024-11-21 7.5 High
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
CVE-2013-0267 1 Apache 1 Vcl 2024-11-21 N/A
The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin, manageGroup, resourceGrant, or userGrant permissions to gain privileges, cause a denial of service, or conduct cross-site scripting (XSS) attacks by leveraging improper data validation.
CVE-2013-0243 1 Haskell 1 Hs-tls 2024-11-21 7.4 High
haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections
CVE-2013-0192 1 Simplemachines 1 Simple Machines Forum 2024-11-21 4.9 Medium
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
CVE-2013-0180 1 Redislabs 1 Redis 2024-11-21 5.5 Medium
Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
CVE-2013-0178 1 Redislabs 1 Redis 2024-11-21 5.5 Medium
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
CVE-2013-0165 1 Redhat 1 Openshift 2024-11-21 7.3 High
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
CVE-2012-6341 1 Netgear 4 Wgr614v7, Wgr614v7 Firmware, Wgr614v9 and 1 more 2024-11-21 6.5 Medium
An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/WPA/WPA2, in plaintext. This is a different issue than CVE-2012-6340.
CVE-2012-6135 2 Phusion, Redhat 2 Passenger, Openshift 2024-11-21 7.5 High
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
CVE-2012-6125 1 Call-cc 1 Chicken 2024-11-21 9.8 Critical
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
CVE-2012-6123 2 Call-cc, Debian 2 Chicken, Debian Linux 2024-11-21 6.5 Medium
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
CVE-2012-6111 2 Debian, Gnome 2 Debian Linux, Gnome Keyring 2024-11-21 7.5 High
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
CVE-2012-6091 1 Magentocommerce 1 Magento 2024-11-21 7.5 High
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.
CVE-2012-6079 1 Boldgrid 1 W3 Total Cache 2024-11-21 7.5 High
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.
CVE-2012-6078 1 Boldgrid 1 W3 Total Cache 2024-11-21 7.5 High
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
CVE-2012-6077 1 Boldgrid 1 W3 Total Cache 2024-11-21 7.5 High
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
CVE-2012-6070 1 Falconpl 1 Falconpl 2024-11-21 7.5 High
Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks.
CVE-2012-5828 1 Blackberry 2 Playbook, Playbook Firmware 2024-11-21 6.5 Medium
BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error
CVE-2012-5699 1 Babygekko 1 Babygekko 2024-11-21 9.8 Critical
BabyGekko before 1.2.4 allows PHP file inclusion.
CVE-2012-5644 4 Debian, Fedoraproject, Libuser Project and 1 more 4 Debian Linux, Fedora, Libuser and 1 more 2024-11-21 5.5 Medium
libuser has information disclosure when moving user's home directory