Search Results (10143 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2012-6140 1 Google 1 Authenticator 2024-08-06 N/A
pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258.
CVE-2012-6337 1 Samsung 4 Galaxy Note 2, Galaxy S, Galaxy S2 and 1 more 2024-08-06 N/A
The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices shows the activation of remote tracking, which might allow physically proximate attackers to defeat a product-recovery effort by tampering with this feature or its location data.
CVE-2012-6341 1 Netgear 4 Wgr614v7, Wgr614v7 Firmware, Wgr614v9 and 1 more 2024-08-06 6.5 Medium
An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/WPA/WPA2, in plaintext. This is a different issue than CVE-2012-6340.
CVE-2012-6097 1 Fedorahosted 1 Cronie 2024-08-06 N/A
File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.
CVE-2012-6105 1 Moodle 1 Moodle 2024-08-06 N/A
blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed.
CVE-2012-6104 1 Moodle 1 Moodle 2024-08-06 N/A
blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed.
CVE-2012-6091 1 Magentocommerce 1 Magento 2024-08-06 7.5 High
Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.
CVE-2012-6079 1 Boldgrid 1 W3 Total Cache 2024-08-06 7.5 High
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.
CVE-2012-6077 1 Boldgrid 1 W3 Total Cache 2024-08-06 7.5 High
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
CVE-2012-5916 1 Neocrome 1 Seditio 2024-08-06 N/A
Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_to_utf8.optional.sql, or (3) system/install/install.parser.sql.
CVE-2012-6078 1 Boldgrid 1 W3 Total Cache 2024-08-06 7.5 High
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
CVE-2012-6049 1 Opensolution 1 Quick.cart 2024-08-06 N/A
Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, which reveals the installation path in an error message.
CVE-2012-5890 2 Stanislas Rolland, Typo3 2 Sr Feuser Register, Typo3 2024-08-06 N/A
The Front End User Registration (sr_feuser_register) extension before 2.6.2 for TYPO3 allows remote attackers to obtain user names and passwords via the (1) edit perspective or (2) autologin feature.
CVE-2012-5915 1 Neocrome 1 Seditio 2024-08-06 N/A
Neocrome Seditio build 161 and earlier allows remote attackers to obtain sensitive information via direct request to (1) view.php, (2) plugins/contact/lang/contact.en.lang.php, (3) system/lang/en/main.lang.php, (4) system/lang/en/message.lang.php, or (5) system/core/view/view.inc.php, which reveals the installation path in an error message.
CVE-2012-5884 1 Mozilla 1 Bugzilla 2024-08-06 N/A
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches of arbitrary users via an XMLRPC request or a JSONRPC request, a different vulnerability than CVE-2012-4198.
CVE-2012-5828 1 Blackberry 2 Playbook, Playbook Firmware 2024-08-06 6.5 Medium
BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error
CVE-2012-5657 1 Zend 1 Zend Framework 2024-08-06 N/A
The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External Entity (XXE) attack.
CVE-2012-5765 1 Ibm 1 Rational Clearquest 2024-08-06 N/A
The Web Client (aka CQ Web) in IBM Rational ClearQuest 7.1.2.x before 7.1.2.9 and 8.0.0.x before 8.0.0.5 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a SQL error message.
CVE-2012-5654 2 Drupal, Nodewords Project 2 Drupal, Nodewords 2024-08-06 N/A
The Nodewords: D6 Meta Tags module before 6.x-1.14 for Drupal, when configured to automatically generate description meta tags from node text, does not properly filter node content when creating tags, which might allow remote attackers to obtain sensitive information by reading the (1) description, (2) dc.description or (3) og:description meta tags.
CVE-2012-5570 1 Basic Webmail Project 1 Basic Webmail 2024-08-06 4.3 Medium
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.