Search Results (323568 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2012-5631 1 Freeipa 1 Freeipa 2024-11-21 8.8 High
ipa 3.0 does not properly check server identity before sending credential containing cookies
CVE-2012-5630 3 Fedoraproject, Libuser Project, Redhat 3 Fedora, Libuser, Enterprise Linux 2024-11-21 6.3 Medium
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
CVE-2012-5628 1 Gofer Project 1 Gofer 2024-11-21 N/A
gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries.
CVE-2012-5626 1 Redhat 6 Jboss Brms, Jboss Enterprise Application Platform, Jboss Enterprise Web Server and 3 more 2024-11-21 7.5 High
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.
CVE-2012-5623 1 Squirrelmail 1 Change Passwd 2024-11-21 7.5 High
Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.
CVE-2012-5618 1 Ushahidi 1 Ushahidi 2024-11-21 9.8 Critical
Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
CVE-2012-5617 2 Fedoraproject, Gksu-polkit Project 2 Fedora, Gksu-polkit 2024-11-21 7.8 High
gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation
CVE-2012-5582 1 Opendnssec 1 Opendnssec 2024-11-21 9.8 Critical
opendnssec misuses libcurl API
CVE-2012-5578 1 Python 1 Keyring 2024-11-21 6.2 Medium
Python keyring has insecure permissions on new databases allowing world-readable files to be created
CVE-2012-5577 2 Debian, Python 2 Debian Linux, Keyring 2024-11-21 7.5 High
Python keyring lib before 0.10 created keyring files with world-readable permissions.
CVE-2012-5570 1 Basic Webmail Project 1 Basic Webmail 2024-11-21 4.3 Medium
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.
CVE-2012-5562 1 Redhat 2 Network Proxy, Satellite 2024-11-21 6.5 Medium
rhn-proxy: may transmit credentials over clear-text when accessing RHN Satellite
CVE-2012-5558 2 Smiley Project, Smileys Project 2 Smiley, Smileys 2024-11-21 4.8 Medium
Cross-site scripting (XSS) vulnerability in the Smiley module 6.x-1.x versions prior to 6.x-1.1 and Smileys module 6.x-1.x versions prior to 6.x-1.1 for Drupal allows remote authenticated users with the "administer smiley" permission to inject arbitrary web script or HTML via a smiley acronym.
CVE-2012-5535 2 Fedoraproject, Gnome 2 Fedora, Gnome-system-log 2024-11-21 7.5 High
gnome-system-log polkit policy allows arbitrary files on the system to be read
CVE-2012-5527 1 Claws-mail 1 Vcalendar 2024-11-21 5.5 Medium
Claws Mail vCalendar plugin: credentials exposed on interface
CVE-2012-5521 3 Debian, Quagga, Redhat 3 Debian Linux, Quagga, Enterprise Linux 2024-11-21 6.5 Medium
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
CVE-2012-5518 1 Ovirt 1 Vdsm 2024-11-21 7.5 High
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
CVE-2012-5476 2 Debian, Openstack 2 Debian Linux, Horizon 2024-11-21 5.5 Medium
Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.
CVE-2012-5474 4 Debian, Fedoraproject, Openstack and 1 more 4 Debian Linux, Fedora, Horizon and 1 more 2024-11-21 5.5 Medium
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
CVE-2012-5389 1 Dart 1 Powertcp Webserver For Activex 2024-11-21 7.5 High
NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted HTTP request.