Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-3846 | 1 Hp | 1 System Management Homepage | 2012-04-12 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 6.2.2.7 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts. | |||||
CVE-2008-7309 | 1 Insoshi | 1 Insoshi | 2012-04-11 | 5.0 MEDIUM | N/A |
Insoshi before 20080920 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the ForumPost user_id value via a modified URL, related to a "mass assignment" vulnerability. | |||||
CVE-2008-7311 | 1 Spreecommerce | 1 Spree | 2012-04-11 | 5.0 MEDIUM | N/A |
The session cookie store implementation in Spree 0.2.0 uses a hardcoded config.action_controller_session hash value (aka secret key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging an application that contains this value within the config/environment.rb file. | |||||
CVE-2012-1030 | 1 Dotnetnuke | 1 Dotnetnuke | 2012-04-11 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in DotNetNuke 6.x through 6.0.2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted URL containing text that is used within a modal popup. | |||||
CVE-2012-1036 | 1 Dotnetnuke | 1 Dotnetnuke | 2012-04-11 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message. | |||||
CVE-2012-1239 | 1 Toshibatec | 64 E-studio-167 With Network Printer Kit, E-studio-167 With Network Printer Kit Firmware, E-studio-181 With Network Printer Kit and 61 more | 2012-04-08 | 10.0 HIGH | N/A |
The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative privileges via unspecified vectors. | |||||
CVE-2011-3318 | 1 Cisco | 4 Video Surveillance 2421, Video Surveillance 2500, Video Surveillance 2600 and 1 more | 2012-04-05 | 7.8 HIGH | N/A |
Cisco Video Surveillance 2421 and 2500 series cameras with software 1.1.x and 2.x before 2.4.0 and Video Surveillance 2600 series cameras with software before 4.2.0-13 allow remote attackers to cause a denial of service (device reload) by sending crafted RTSP packets over TCP, aka Bug IDs CSCtj96312, CSCtj39462, and CSCtl80175. | |||||
CVE-2011-3319 | 1 Cisco | 1 Webex Recording Format Player | 2012-04-05 | 9.3 HIGH | N/A |
Buffer overflow in the WRF parsing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute arbitrary code via a crafted WRF file. | |||||
CVE-2011-4004 | 1 Cisco | 1 Webex Recording Format Player | 2012-04-05 | 9.3 HIGH | N/A |
Buffer overflow in the ATAS32 processing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute arbitrary code via a crafted WRF file. | |||||
CVE-2008-7270 | 1 Openssl | 1 Openssl | 2012-04-05 | 4.3 MEDIUM | N/A |
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180. | |||||
CVE-2012-2054 | 1 Redmine | 1 Redmine | 2012-04-05 | 5.0 MEDIUM | N/A |
Redmine before 1.3.2 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set attributes in the (1) Comment, (2) Document, (3) IssueCategory, (4) MembersController, (5) Message, (6) News, (7) TimeEntry, (8) Version, (9) Wiki, (10) UserPreference, or (11) Board model via a modified URL, related to a "mass assignment" vulnerability, a different vulnerability than CVE-2012-0327. | |||||
CVE-2008-7310 | 1 Spreecommerce | 1 Spree | 2012-04-05 | 5.0 MEDIUM | N/A |
Spree 0.2.0 does not properly restrict the use of a hash to provide values for a model's attributes, which allows remote attackers to set the Order state value and bypass the intended payment step via a modified URL, related to a "mass assignment" vulnerability. | |||||
CVE-2012-1907 | 1 Privawall | 1 Privawall Antivirus | 2012-04-04 | 4.3 MEDIUM | N/A |
The scanner engine in PrivaWall Antivirus 5.6 and earlier does not recognize the Office XML (aka Open Document XML) file format, which allows remote attackers to bypass malware detection via a crafted file embedded in a WordML document. | |||||
CVE-2011-4042 | 1 Arcinfo | 3 Frontvue, Pcvue, Plantvue | 2012-04-02 | 9.3 HIGH | N/A |
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer. | |||||
CVE-2011-4043 | 1 Arcinfo | 3 Frontvue, Pcvue, Plantvue | 2012-04-02 | 9.3 HIGH | N/A |
Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code via a large value for an integer parameter, leading to a buffer overflow. | |||||
CVE-2011-4044 | 1 Arcinfo | 3 Frontvue, Pcvue, Plantvue | 2012-04-02 | 5.8 MEDIUM | N/A |
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify files via calls to unknown methods. | |||||
CVE-2011-4045 | 1 Arcinfo | 3 Frontvue, Pcvue, Plantvue | 2012-04-02 | 4.3 MEDIUM | N/A |
Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a denial of service via a crafted HTML document. | |||||
CVE-2011-4535 | 2 Craig Peterson, Scadatec | 3 Turbopower Abbrevia, Modbustagserver, Scadaphone | 2012-04-02 | 6.8 MEDIUM | N/A |
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earlier, and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP file. | |||||
CVE-2012-0221 | 1 Rockwellautomation | 2 Factorytalk, Rslogix 5000 | 2012-04-02 | 5.0 MEDIUM | N/A |
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause a denial of service (service outage) via a crafted packet. | |||||
CVE-2012-0222 | 1 Rockwellautomation | 2 Factorytalk, Rslogix 5000 | 2012-04-02 | 5.0 MEDIUM | N/A |
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted packet. |