CVE-2012-2947
- EPSS 4.3%
- Veröffentlicht 02.06.2012 15:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
chan_iax2.c in the IAX2 channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1, when a certain mohinterpret setting is enabled, allows remote attackers to cause a den...
- EPSS 0.49%
- Veröffentlicht 29.05.2012 20:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute ar...
CVE-2012-0879
- EPSS 0.06%
- Veröffentlicht 17.05.2012 11:00:36
- Zuletzt bearbeitet 11.04.2025 00:51:21
The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context...
CVE-2012-1823
- EPSS 94.39%
- Veröffentlicht 11.05.2012 10:15:48
- Zuletzt bearbeitet 04.11.2025 18:15:34
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by ...
CVE-2012-0216
- EPSS 0.05%
- Veröffentlicht 22.04.2012 18:55:03
- Zuletzt bearbeitet 27.08.2025 11:17:02
The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow ...
- EPSS 3.06%
- Veröffentlicht 17.04.2012 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
CVE-2011-3045
- EPSS 4.46%
- Veröffentlicht 22.03.2012 16:55:01
- Zuletzt bearbeitet 09.06.2025 16:15:22
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly exe...
- EPSS 8.57%
- Veröffentlicht 01.02.2012 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corr...
CVE-2012-0449
- EPSS 4.29%
- Veröffentlicht 01.02.2012 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...
CVE-2012-0442
- EPSS 1.44%
- Veröffentlicht 01.02.2012 16:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corru...