Search Results (76118 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2012-3822 1 Arialsoftware 1 Campaign Enterprise 2024-08-06 7.5 High
Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials.
CVE-2012-3809 1 Samsung 1 Kies 2024-08-06 7.5 High
Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.
CVE-2012-3808 1 Samsung 1 Kies 2024-08-06 7.5 High
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.
CVE-2012-3810 1 Samsung 1 Kies 2024-08-06 7.5 High
Samsung Kies before 2.5.0.12094_27_11 has registry modification.
CVE-2012-3824 1 Arialsoftware 1 Campaign Enterprise 2024-08-06 7.5 High
In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.
CVE-2012-3823 1 Arialsoftware 1 Campaign Enterprise 2024-08-06 7.5 High
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
CVE-2012-3543 3 Canonical, Debian, Mono-project 3 Ubuntu Linux, Debian Linux, Mono 2024-08-06 7.5 High
mono 2.10.x ASP.NET Web Form Hash collision DoS
CVE-2012-3462 1 Fedoraproject 1 Sssd 2024-08-06 8.8 High
A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.
CVE-2012-3490 1 Wisc 1 Htcondor 2024-08-06 8.8 High
The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the return value of setuid calls, which might cause a subprocess to be created with root privileges and allow remote attackers to gain privileges via unspecified vectors.
CVE-2012-3409 2 Debian, Ecryptfs 2 Debian Linux, Ecryptfs-utils 2024-08-06 7.8 High
ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation
CVE-2012-3407 1 Plow Project 1 Plow 2024-08-06 7.8 High
plow has local buffer overflow vulnerability
CVE-2012-2979 1 Freebsd 1 Name Server Daemon 2024-08-06 7.5 High
FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.
CVE-2012-2945 1 Apache 1 Hadoop 2024-08-06 7.5 High
Hadoop 1.0.3 contains a symlink vulnerability.
CVE-2012-2950 2 Gatewaygeomatics, Microsoft 2 Mapserver, Windows 2024-08-06 8.1 High
Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information.
CVE-2012-2931 1 Tinywebgallery 1 Tinywebgallery 2024-08-06 7.2 High
PHP code injection in TinyWebGallery before 1.8.8 allows remote authenticated users with admin privileges to inject arbitrary code into the .htusers.php file.
CVE-2012-2656 1 Talend 1 Restlet 2024-08-06 7.5 High
An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.
CVE-2012-2629 1 Axous 1 Axous 2024-08-06 8.8 High
Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities in Axous 1.1.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator account via an addnew action to admin/administrators_add.php; or (2) conduct cross-site scripting (XSS) attacks via the page_title parameter to admin/content_pages_edit.php; the (3) category_name[] parameter to admin/products_category.php; the (4) site_name, (5) seo_title, or (6) meta_keywords parameter to admin/settings_siteinfo.php; the (7) company_name, (8) address1, (9) address2, (10) city, (11) state, (12) country, (13) author_first_name, (14) author_last_name, (15) author_email, (16) contact_first_name, (17) contact_last_name, (18) contact_email, (19) general_email, (20) general_phone, (21) general_fax, (22) sales_email, (23) sales_phone, (24) support_email, or (25) support_phone parameter to admin/settings_company.php; or the (26) system_email, (27) sender_name, (28) smtp_server, (29) smtp_username, (30) smtp_password, or (31) order_notice_email parameter to admin/settings_email.php.
CVE-2024-6315 1 Unitecms 1 Blox Page Builder 2024-08-06 8.8 High
The Blox Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handleUploadFile' function in all versions up to, and including, 1.0.65. This makes it possible for authenticated attackers, with contributor-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVE-2024-7335 1 Totolink 1 Ex200 Firmware 2024-08-06 8.8 High
A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation of the argument http_host leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-273258 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2015-10123 1 Wago 10 750-352 Firmware, 750-829 Firmware, 750-831 Firmware and 7 more 2024-08-06 8.8 High
An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page of the web-based management a buffer overflow will be triggered to gain full access of the device.