CVE-2012-0053
- EPSS 55.96%
- Veröffentlicht 28.01.2012 04:05:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors i...
CVE-2012-0031
- EPSS 1.2%
- Veröffentlicht 18.01.2012 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memor...
- EPSS 0.18%
- Veröffentlicht 08.01.2012 11:55:19
- Zuletzt bearbeitet 11.04.2025 00:51:21
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an...
- EPSS 0.61%
- Veröffentlicht 08.01.2012 11:55:18
- Zuletzt bearbeitet 11.04.2025 00:51:21
MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.
CVE-2011-3919
- EPSS 3.19%
- Veröffentlicht 07.01.2012 11:55:13
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
- EPSS 92.59%
- Veröffentlicht 25.12.2011 01:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to exec...
- EPSS 3.64%
- Veröffentlicht 24.12.2011 19:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service (segmentation fault) via...
CVE-2011-4516
- EPSS 47.82%
- Veröffentlicht 15.12.2011 03:57:34
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding st...
CVE-2011-4517
- EPSS 42.13%
- Veröffentlicht 15.12.2011 03:57:34
- Zuletzt bearbeitet 11.04.2025 00:51:21
The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a deni...
- EPSS 1.21%
- Veröffentlicht 13.12.2011 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.