Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-2491 | 1 Roundup-tracker | 1 Roundup | 2012-05-30 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program. | |||||
CVE-2011-3772 | 1 Php-collab | 1 Phpcollab | 2012-05-30 | 5.0 MEDIUM | N/A |
phpCollab 2.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by topics/noti_newtopic.php and certain other files. | |||||
CVE-2011-3779 | 1 Idevspot | 1 Phphostbot | 2012-05-30 | 5.0 MEDIUM | N/A |
PhpHostBot 2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/create_acct.php and certain other files. | |||||
CVE-2011-4019 | 1 Cisco | 2 Ios, Unified Communications Manager | 2012-05-29 | 5.4 MEDIUM | N/A |
Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted response to a SIP SUBSCRIBE message, aka Bug IDs CSCto93837 and CSCtj61883. | |||||
CVE-2012-2949 | 2 Google, Zte | 2 Android, Score M | 2012-05-29 | 10.0 HIGH | N/A |
The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application. | |||||
CVE-2012-0657 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-05-29 | 2.1 LOW | N/A |
Quartz Composer in Apple Mac OS X before 10.7.4, when the RSS Visualizer screensaver is enabled, allows physically proximate attackers to bypass screen locking and launch a Safari process via unspecified vectors. | |||||
CVE-2012-0658 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-05-29 | 6.8 MEDIUM | N/A |
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted audio sample tables in a movie file that is progressively downloaded. | |||||
CVE-2012-0659 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-05-29 | 6.8 MEDIUM | N/A |
Integer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file. | |||||
CVE-2012-0660 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-05-29 | 6.8 MEDIUM | N/A |
Buffer underflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file. | |||||
CVE-2012-0662 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-05-29 | 7.5 HIGH | N/A |
Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted input. | |||||
CVE-2012-0675 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-05-29 | 4.3 MEDIUM | N/A |
Time Machine in Apple Mac OS X before 10.7.4 does not require continued use of SRP-based authentication after this authentication method is first used, which allows remote attackers to read Time Capsule credentials by spoofing the backup volume. | |||||
CVE-2011-4232 | 1 Cisco | 1 Unified Meetingplace | 2012-05-29 | 5.0 MEDIUM | N/A |
The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists, which allows remote attackers to enumerate directory names via a series of queries, aka Bug ID CSCtt94070. | |||||
CVE-2012-2435 | 1 Pligg | 1 Pligg Cms | 2012-05-28 | 6.5 MEDIUM | N/A |
Directory traversal vulnerability in the captcha module in Pligg CMS before 1.2.2 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the captcha parameter to module.php, as demonstrated by cross-site request forgery (CSRF) attacks. | |||||
CVE-2012-1413 | 1 Zen-cart | 1 Zen Cart | 2012-05-27 | 2.6 LOW | N/A |
Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_username parameter to zc_install/index.php. | |||||
CVE-2012-1792 | 1 Oscommerce | 1 Online Merchant | 2012-05-27 | 2.6 LOW | N/A |
Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in OSCommerce Online Merchant 3.0.2, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the name parameter to oscommerce/index.php, which is not properly handled in an error message. NOTE: this might not be a vulnerability, since the ability to access oscommerce/index.php during installation may already imply administrator privileges. | |||||
CVE-2012-1824 | 1 Measuresoft | 2 Scadapro Client, Scadapro Server | 2012-05-27 | 7.2 HIGH | N/A |
Untrusted search path vulnerability in Measuresoft ScadaPro Client before 4.0.0 and ScadaPro Server before 4.0.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |||||
CVE-2012-2235 | 1 Sitracker | 1 Support Incident Tracker | 2012-05-27 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Support Incident Tracker (SiT!) 3.65 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter to index.php, which is not properly handled in an error message. | |||||
CVE-2012-2426 | 1 Xarrow | 1 Xarrow | 2012-05-27 | 7.8 HIGH | N/A |
The server in xArrow before 3.4.1 does not properly allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via unspecified vectors. | |||||
CVE-2012-2427 | 1 Xarrow | 1 Xarrow | 2012-05-27 | 10.0 HIGH | N/A |
Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger an invalid free operation. | |||||
CVE-2012-2428 | 1 Xarrow | 1 Xarrow | 2012-05-27 | 10.0 HIGH | N/A |
Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers an out-of-bounds read operation. |