CVE-2012-1823
- EPSS 94.39%
- Published 11.05.2012 10:15:48
- Last modified 11.04.2025 00:51:21
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by ...
CVE-2012-0216
- EPSS 0.05%
- Published 22.04.2012 18:55:03
- Last modified 27.08.2025 11:17:02
The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow ...
- EPSS 1.98%
- Published 17.04.2012 21:55:01
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
CVE-2011-3045
- EPSS 5.81%
- Published 22.03.2012 16:55:01
- Last modified 09.06.2025 16:15:22
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly exe...
- EPSS 2.23%
- Published 01.02.2012 16:55:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corr...
CVE-2012-0449
- EPSS 10.94%
- Published 01.02.2012 16:55:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...
CVE-2012-0442
- EPSS 1.44%
- Published 01.02.2012 16:55:00
- Last modified 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corru...
CVE-2012-0053
- EPSS 70.5%
- Published 28.01.2012 04:05:00
- Last modified 11.04.2025 00:51:21
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors i...
CVE-2012-0031
- EPSS 2.18%
- Published 18.01.2012 20:55:02
- Last modified 11.04.2025 00:51:21
scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memor...
- EPSS 0.24%
- Published 08.01.2012 11:55:19
- Last modified 11.04.2025 00:51:21
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an...