CVE-2012-4415
- EPSS 38.64%
- Veröffentlicht 01.10.2012 03:26:16
- Zuletzt bearbeitet 29.04.2026 01:13:23
Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name.
CVE-2012-1149
- EPSS 1.19%
- Veröffentlicht 21.06.2012 15:55:11
- Zuletzt bearbeitet 29.04.2026 01:13:23
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a cra...
CVE-2012-0037
- EPSS 0.9%
- Veröffentlicht 17.06.2012 03:41:40
- Zuletzt bearbeitet 29.04.2026 01:13:23
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity ...
- EPSS 0.49%
- Veröffentlicht 29.05.2012 20:55:08
- Zuletzt bearbeitet 29.04.2026 01:13:23
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute ar...
CVE-2012-1146
- EPSS 0.1%
- Veröffentlicht 17.05.2012 11:00:37
- Zuletzt bearbeitet 29.04.2026 01:13:23
The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer de...
CVE-2012-1823
- EPSS 94.36%
- Veröffentlicht 11.05.2012 10:15:48
- Zuletzt bearbeitet 21.04.2026 20:28:53
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by ...
- EPSS 3.06%
- Veröffentlicht 17.04.2012 21:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
CVE-2012-2089
- EPSS 5.32%
- Veröffentlicht 17.04.2012 21:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly exe...
CVE-2011-3045
- EPSS 4.46%
- Veröffentlicht 22.03.2012 16:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly exe...
- EPSS 92.59%
- Veröffentlicht 25.12.2011 01:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to exec...