260521
|
- |
|
david_alkire
|
drag_\&_drop_gallery
|
SQL injection vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2012-4479
|
2012-12-4 04:24 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260522
|
- |
|
david_alkire
|
drag_\&_drop_gallery
|
Cross-site request forgery (CSRF) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to hijack the authentication of administrators.
|
CWE-352
Origin Validation Error
|
CVE-2012-4478
|
2012-12-4 04:13 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260523
|
- |
|
simon_rycroft
|
hashcash
|
Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when "Log failed hashcash" is enabled, allows remote attackers to inject …
|
CWE-79
Cross-site Scripting
|
CVE-2012-4469
|
2012-12-3 14:00 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260524
|
- |
|
security_questions_project
|
security_questions
|
The Security Questions module for Drupal 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.1 does not properly restrict access, which allows remote attackers to edit an arbitrary user's questions and a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4475
|
2012-12-3 14:00 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260525
|
- |
|
david_alkire
|
drag_\&_drop_gallery
|
Cross-site scripting (XSS) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2012-4476
|
2012-12-3 14:00 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260526
|
- |
|
david_alkire
|
drag_\&_drop_gallery
|
Unspecified vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to bypass access restrictions via unknown attack vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-4477
|
2012-12-3 14:00 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260527
|
- |
|
ps_project_management_team
|
libunity-webapps
|
Use-after-free vulnerability in libunity-webapps before 2.4.1 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted web …
|
CWE-399
Resource Management Errors
|
CVE-2012-4551
|
2012-12-3 14:00 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260528
|
- |
|
python
|
keyring
|
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.
|
CWE-310
Cryptographic Issues
|
CVE-2012-4571
|
2012-12-3 14:00 |
2012-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260529
|
- |
|
kyocera
|
ah-k3001v ah-k3002v xw300k xw310k xw320k xw320kr
|
The KYOCERA AH-K3001V, AH-K3002V, WX300K, WX310K, WX320K, and WX320KR devices allow remote attackers to cause a denial of service (persistent reboot) via an e-mail message in an invalid format.
|
NVD-CWE-noinfo
|
CVE-2012-5174
|
2012-11-30 23:02 |
2012-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260530
|
- |
|
apple
|
safari
|
WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to obtain sensitive information about full pathnames via a crafted web sit…
|
CWE-200
Information Exposure
|
CVE-2012-3694
|
2012-11-30 14:00 |
2012-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|