CVE-2012-2751
- EPSS 1.76%
- Veröffentlicht 22.07.2012 16:55:27
- Zuletzt bearbeitet 11.04.2025 00:51:21
ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote a...
CVE-2012-0867
- EPSS 1.87%
- Veröffentlicht 18.07.2012 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters...
- EPSS 0.33%
- Veröffentlicht 12.07.2012 20:55:15
- Zuletzt bearbeitet 11.04.2025 00:51:21
The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal ...
CVE-2012-2143
- EPSS 8.18%
- Veröffentlicht 05.07.2012 14:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for cont...
CVE-2012-0876
- EPSS 0.3%
- Veröffentlicht 03.07.2012 19:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file wit...
CVE-2012-1149
- EPSS 2.71%
- Veröffentlicht 21.06.2012 15:55:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a cra...
CVE-2012-0037
- EPSS 0.53%
- Veröffentlicht 17.06.2012 03:41:40
- Zuletzt bearbeitet 11.04.2025 00:51:21
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity ...
- EPSS 93.78%
- Veröffentlicht 07.06.2012 22:55:17
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability ...
CVE-2012-1610
- EPSS 7.03%
- Veröffentlicht 05.06.2012 22:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: th...
CVE-2012-1798
- EPSS 1.41%
- Veröffentlicht 05.06.2012 22:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted EXIF IFD in a TIFF image.