- EPSS 13.67%
- Published 28.12.2012 11:48:44
- Last modified 11.04.2025 00:51:21
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
CVE-2012-3354
- EPSS 0.55%
- Published 20.11.2012 00:55:00
- Last modified 11.04.2025 00:51:21
doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message.
CVE-2012-4406
- EPSS 7.79%
- Published 22.10.2012 23:55:06
- Last modified 11.04.2025 00:51:21
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
CVE-2012-4453
- EPSS 0.04%
- Published 09.10.2012 23:55:05
- Last modified 11.04.2025 00:51:21
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
CVE-2012-4415
- EPSS 38.64%
- Published 01.10.2012 03:26:16
- Last modified 11.04.2025 00:51:21
Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name.
CVE-2012-1149
- EPSS 2.71%
- Published 21.06.2012 15:55:11
- Last modified 11.04.2025 00:51:21
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a cra...
CVE-2012-0037
- EPSS 0.53%
- Published 17.06.2012 03:41:40
- Last modified 11.04.2025 00:51:21
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity ...
- EPSS 0.49%
- Published 29.05.2012 20:55:08
- Last modified 11.04.2025 00:51:21
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute ar...
CVE-2012-1146
- EPSS 0.1%
- Published 17.05.2012 11:00:37
- Last modified 11.04.2025 00:51:21
The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer de...
CVE-2012-1823
- EPSS 94.39%
- Published 11.05.2012 10:15:48
- Last modified 11.04.2025 00:51:21
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by ...