CVE-2012-2317
- EPSS 0.25%
- Veröffentlicht 07.08.2012 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Debian php_crypt_revamped.patch patch for PHP 5.3.x, as used in the php5 package before 5.3.3-7+squeeze4 in Debian GNU/Linux squeeze, the php5 package before 5.3.2-1ubuntu4.17 in Ubuntu 10.04 LTS, and the php5 package before 5.3.5-1ubuntu7.10 in ...
CVE-2012-2665
- EPSS 5.02%
- Veröffentlicht 06.08.2012 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Do...
CVE-2012-3867
- EPSS 1.42%
- Veröffentlicht 06.08.2012 16:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it eas...
CVE-2012-3571
- EPSS 22.14%
- Veröffentlicht 25.07.2012 10:42:35
- Zuletzt bearbeitet 11.04.2025 00:51:21
ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.
CVE-2012-3954
- EPSS 6.48%
- Veröffentlicht 25.07.2012 10:42:35
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.
CVE-2012-0876
- EPSS 0.32%
- Veröffentlicht 03.07.2012 19:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file wit...
- EPSS 0.25%
- Veröffentlicht 19.06.2012 20:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /var/log/dist-upgrade directory when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by vie...
CVE-2011-4408
- EPSS 0.41%
- Veröffentlicht 16.06.2012 00:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Single Sign On Client (ubuntu-sso-client) for Ubuntu 11.04 and 11.10 does not properly validate SSL certificates when using HTTPS, which allows remote attackers to spoof a server and modify or read sensitive data via a man-in-the-middle (MITM) at...
CVE-2011-4409
- EPSS 0.65%
- Veröffentlicht 16.06.2012 00:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle (MITM) attack.
CVE-2011-3193
- EPSS 4.64%
- Veröffentlicht 16.06.2012 00:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a craft...