Export limit exceeded: 24706 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (24706 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2012-4030 1 Chamilo 1 Chamilo Lms 2024-11-21 7.5 High
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.
CVE-2012-3543 3 Canonical, Debian, Mono-project 3 Ubuntu Linux, Debian Linux, Mono 2024-11-21 7.5 High
mono 2.10.x ASP.NET Web Form Hash collision DoS
CVE-2012-3460 1 Redhat 1 Enterprise Mrg 2024-11-21 9.8 Critical
cumin: At installation postgresql database user created without password
CVE-2012-3409 2 Debian, Ecryptfs 2 Debian Linux, Ecryptfs-utils 2024-11-21 7.8 High
ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation
CVE-2012-3353 1 Apache 1 Sling Jcr Contentloader 2024-11-21 N/A
The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information leaks. Users should upgrade to version 2.1.6 of the JCR ContentLoader
CVE-2012-3338 1 Ibm 1 Infosphere Guardium 2024-11-21 5.3 Medium
IBM InfoSphere Guardium 8.0, 8.01, and 8.2 could allow a remote attacker to bypass security restrictions, caused by improper restrictions on the create new user account functionality. An attacker could exploit this vulnerability to create unprivileged user accounts. IBM X-Force ID: 78286.
CVE-2012-3331 1 Ibm 1 Sametime 2024-11-21 N/A
IBM Sametime allows remote attackers to obtain sensitive information from the Sametime Log database via a direct request to STLOG.NSF. IBM X-Force ID: 78048.
CVE-2012-2724 1 Md-systems 1 Simplenews 2024-11-21 5.3 Medium
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.
CVE-2012-2350 2 Debian, Pam Shield Project 2 Debian Linux, Pam Shield 2024-11-21 7.5 High
pam_shield before 0.9.4: Default configuration does not perform protective action
CVE-2012-2248 2 Debian, Dhclient Project 2 Debian Linux, Dhclient 2024-11-21 8.1 High
An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
CVE-2012-1994 1 Hp 1 Systems Insight Manager 2024-11-21 5.7 Medium
HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information
CVE-2012-1326 1 Cisco 1 Ironport Web Security Appliance 2024-11-21 7.4 High
Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead to MITM attacks
CVE-2012-1169 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-11-21 5.3 Medium
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
CVE-2012-1168 3 Fedoraproject, Moodle, Redhat 3 Fedora, Moodle, Enterprise Linux 2024-11-21 8.2 High
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
CVE-2012-1161 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-11-21 4.3 Medium
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
CVE-2012-1159 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-11-21 4.3 Medium
Moodle before 2.2.2: Overview report allows users to see hidden courses
CVE-2012-1158 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-11-21 4.3 Medium
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
CVE-2012-1155 4 Debian, Fedoraproject, Moodle and 1 more 4 Debian Linux, Fedora, Moodle and 1 more 2024-11-21 7.5 High
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
CVE-2012-1105 3 Apereo, Debian, Fedoraproject 3 Phpcas, Debian Linux, Fedora 2024-11-21 5.5 Medium
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.
CVE-2012-1094 1 Redhat 1 Jboss Application Server 2024-11-21 7.5 High
JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.