Latest CVE Feed
-
5.5
MEDIUMCVE-2012-0945
whoopsie-daisy before 0.1.26: Root user can remove arbitrary files... Read more
Affected Products : whoopsie-daisy- EPSS Score: %0.19
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-0941
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or ... Read more
Affected Products : fortios- EPSS Score: %0.86
- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGH- EPSS Score: %0.54
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2012-0844
Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.... Read more
- EPSS Score: %0.15
- Published: Feb. 21, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUM- EPSS Score: %0.15
- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUM- EPSS Score: %0.10
- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-0828
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing character... Read more
- EPSS Score: %5.89
- Published: Feb. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.51
- Published: Nov. 19, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- EPSS Score: %0.58
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2012-0810
The int3 handler in the Linux kernel before 3.3 relies on a per-CPU debug stack, which allows local users to cause a denial of service (stack corruption and panic) via a crafted application that triggers certain lock contention.... Read more
Affected Products : linux_kernel- EPSS Score: %0.05
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2012-0785
Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Has... Read more
- EPSS Score: %1.94
- Published: Feb. 24, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2012-0771
Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0759.... Read more
Affected Products : shockwave_player- EPSS Score: %6.37
- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2012-0718
IBM Tivoli Endpoint Manager 8 does not set the HttpOnly flag on cookies.... Read more
Affected Products : tivoli_endpoint_manager- EPSS Score: %0.19
- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2012-0699
Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add news via an add action to familynews.php or (2... Read more
Affected Products : family_connections_cms- EPSS Score: %0.49
- Published: Jan. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-0694
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.... Read more
Affected Products : sugarcrm- EPSS Score: %83.75
- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2012-0433
The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allowing local users to read confidential data.... Read more
Affected Products : crowbar- EPSS Score: %0.03
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2012-0334
Cisco IronPort Web Security Appliance AsyncOS software prior to 7.5 has a SSL Certificate Caching vulnerability which could allow man-in-the-middle attacks... Read more
Affected Products : ironport_web_security_appliance- EPSS Score: %0.06
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-0070
spamdyke prior to 4.2.1: STARTTLS reveals plaintext... Read more
Affected Products : spamdyke- EPSS Score: %0.22
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2012-0063
Insecure plugin update mechanism in tucan through 0.3.10 could allow remote attackers to perform man-in-the-middle attacks and execute arbitrary code ith the permissions of the user running tucan.... Read more
Affected Products : tucan- EPSS Score: %2.43
- Published: Feb. 21, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2012-0055
OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.... Read more
- EPSS Score: %0.39
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024