Search Results (10142 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2012-1614 1 Coppermine-gallery 1 Coppermine Photo Gallery 2024-08-06 N/A
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter to usermgr.php, or an invalid (5) newer_than or (6) older_than parameter to search.inc.php, which reveals the installation path in an error message.
CVE-2012-1586 2 Debian, Redhat 2 Cifs-utils, Enterprise Linux 2024-08-06 N/A
mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message.
CVE-2012-1513 1 Vmware 1 Vcenter Orchestrator 2024-08-06 N/A
The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive information by reading this document.
CVE-2012-1579 1 Mediawiki 1 Mediawiki 2024-08-06 N/A
The resource loader in MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 includes private data such as CSRF tokens in a JavaScript file, which allows remote attackers to obtain sensitive information.
CVE-2024-36121 1 Netty 1 Netty-incubator-codec-ohttp 2024-08-06 5.9 Medium
netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and uses this sequence number to calculate the appropriate nonce to use with the encryption algorithm. Unfortunately, two separate errors combine which would allow an attacker to cause the sequence number to overflow and thus the nonce to repeat.
CVE-2012-1348 1 Cisco 1 Wide Area Application Services 2024-08-06 N/A
Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which might allow remote attackers to obtain sensitive information via a brute-force attack on the hash string, aka Bug ID CSCty17279.
CVE-2012-1361 1 Cisco 1 Ios 2024-08-06 N/A
Cisco IOS 15.1 and 15.2, when the Multicast Music-on-Hold (MMoH) feature of Cisco Unified Communications Manager (CUCM) is enabled, allows remote attackers to obtain sensitive crosstalk information by listening during a PSTN call, aka Bug ID CSCtx77750.
CVE-2012-1223 1 Rabidhamster 1 R2\/extreme 2024-08-06 N/A
RabidHamster R2/Extreme 1.65 and earlier uses a small search space of values for the PIN number, which allows remote attackers to obtain the PIN number via a brute force attack.
CVE-2012-1243 2 Google, Studiohitori 2 Android, Twitrocker2 Android 2024-08-06 N/A
The TwitRocker2 application before 1.0.23 for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.
CVE-2012-1249 2 Google, Lunascape 2 Android, Ilunascape Android 2024-08-06 N/A
The iLunascape application 1.0.4.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive stored information via a crafted application.
CVE-2012-1169 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-08-06 5.3 Medium
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
CVE-2012-1159 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-08-06 4.3 Medium
Moodle before 2.2.2: Overview report allows users to see hidden courses
CVE-2012-1155 4 Debian, Fedoraproject, Moodle and 1 more 4 Debian Linux, Fedora, Moodle and 1 more 2024-08-06 7.5 High
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
CVE-2012-1161 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-08-06 4.3 Medium
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
CVE-2012-1158 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-08-06 4.3 Medium
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
CVE-2012-1094 1 Redhat 1 Jboss Application Server 2024-08-06 7.5 High
JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.
CVE-2012-1111 1 Robert Ancell 1 Lightdm 2024-08-06 N/A
lightdm before 1.0.9 does not properly close file descriptors before opening a child process, which allows local users to write to the lightdm log or have other unspecified impact.
CVE-2012-0959 1 Remote Login Service Hackers 1 Remote Login Service 2024-08-06 N/A
Remote Login Service (RLS) 1.0.0 does not properly clear account information when switching users, which might allow physically proximate users to obtain login credentials.
CVE-2012-1105 3 Apereo, Debian, Fedoraproject 3 Phpcas, Debian Linux, Fedora 2024-08-06 5.5 Medium
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.
CVE-2012-0961 1 Debian 2 Advanced Package Tool, Apt 2024-08-06 N/A
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.